Impact
The flaw is a heap‑based buffer overflow in the Windows Storage Management Provider. An attacker with local authorisation can craft an input that corrupts memory on the heap and, as a result, gains elevated privileges on the affected system. This allows the attacker to execute arbitrary code with higher privileges, enabling control over the machine, persistence, or lateral movement within the network. The weakness is an instance of CWE‑122: Heap Buffer Overflow.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1) and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both full and Server Core installations).
Risk and Exploitability
CVSS score of 7.8 indicates a high risk, but the EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalogue. Based on the description, the attack vector requires local access and an authorised user; exploitation would involve triggering the heap overflow via the storage provider, after which elevated privileges are gained. No public exploit code or remote trigger has been reported, so the risk level is moderated by the local‑only reachability.
OpenCVE Enrichment