Impact
Heap-based buffer overflow in the Windows VOLSNAP.SYS driver allows an attacker with local user privileges to execute arbitrary code at higher privilege levels, potentially gaining full control of the affected system. The flaw, classified as CWE-122, can be triggered by manipulating the driver’s heap allocations during normal operation. It does not provide remote access but can be abused by legitimate users who are able to influence the driver through system activity. Because the code executes with elevated privileges once the overflow is exploited, an attacker can modify system files, install malware, or compromise other users.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. The vulnerability exists in the VOLSNAP.SYS component across these platforms and is not limited to a specific architecture listed, except where noted in the Windows 10 and 11 entries. Users of these systems should verify whether their configuration includes the VOLSNAP.SYS driver and whether the affected releases are in use.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for a local privilege escalation. Without an EPSS score, the exact likelihood of exploitation cannot be quantified, but the flaw is not listed in the CISA KEV catalog, suggesting that a publicly known exploit has not yet been confirmed. The attack vector is local with an authenticated user, meaning that an attacker with valid credentials could launch the exploit from the target machine. Given the high privilege elevation, the risk to system confidentiality, integrity, and availability is significant for affected users.
OpenCVE Enrichment