Impact
A null pointer dereference in the Virtual Hard Disk (VHD) Miniport Driver can be triggered by an unauthorized local attacker, causing the driver to crash and the system to become unresponsive. The impact is a local denial of service that may prevent legitimate users from accessing virtual disk services and can disrupt critical workloads dependent on VHD functionality. This weakness is categorized as CWE-476, emphasizing improper handling of null references.
Affected Systems
The multiple Microsoft Windows product families, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, across various architecture flavors such as x86, x64, and arm64. The list is drawn from the CNA vendor/product enumeration provided.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score is currently unavailable, so the real-world exploitation probability is uncertain. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Inferred from the local qualifier, the likely attack vector is a local privilege escalation or an unprivileged local attacker who can manipulate VHD operations, triggering the driver crash.
OpenCVE Enrichment