Impact
An integer overflow or wraparound in the Volume Manager Driver allows a local user with sufficient privileges to manipulate internal data structures. By triggering the overflow, the attacker can gain higher privileges on the affected Windows systems. The vulnerability is identified as CWE‑190 and presents a significant risk of escalating local privileges to administrative or system level, potentially compromising the entire machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and 23H2 again; Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 and their server core installations. These systems use the native Volume Manager Driver component that is affected.
Risk and Exploitability
The likely attack vector is local code execution by an authorized user, inferred from the description. The CVSS score of 7.8 indicates a high severity vulnerability with the potential for significant impact. No EPSS score is available, so the exact likelihood of exploitation cannot be quantitatively assessed, but the CVE is not listed in the CISA KEV catalog. The attack requires an authenticated or authorized local user and local code execution, meaning the risk is confined to the local environment. However, once escalated, the attacker can execute arbitrary code with elevated privileges.
OpenCVE Enrichment