Impact
A heap‑based buffer overflow exists in the Volume Manager Driver that can be triggered by an attacker who has legitimate access to the network. The flaw permits the attacker to alter memory during a data transaction, leading to privilege escalation on the target machine. The vulnerability is rated CVSS 8.0, indicating a high severity impact if successfully exploited.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including server core installations where applicable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but its CVSS score of 8.0 indicates significant risk. The likely attack vector is over the network by an authorized attacker who can send crafted requests to the Volume Manager Driver. This requires authenticated access to the host segment. Because the flaw lies in heap management, a successful exploit could grant the attacker system‑level privileges, compromising confidentiality, integrity, and availability of the affected systems. No public exploit has been reported yet, but the severity justifies proactive remediation.
OpenCVE Enrichment