Impact
A heap‑based buffer overflow in Windows Distributed File System (DFS) allows an attacker who is already authenticated on a local machine to execute arbitrary code with elevated privileges. The vulnerability is a classic CWE‑122 type overflow, giving the attacker the ability to corrupt critical memory objects and gain administrative rights. Impact includes the ability to modify system files, install malware, and wipe or tamper with sensitive data, thereby compromising confidentiality, integrity and availability on the compromised host.
Affected Systems
A range of Microsoft Windows editions are affected, including Windows 10 versions 1607, 1809, 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and several server releases such as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Core installations). All 32‑bit and 64‑bit builds listed in the CNA product list are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk when exploited. EPSS is not available, implying no current exploitation data in the public pool, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local authorized user exploiting the DFS service, which runs with system privileges. Consequently, while public exploits are not documented, the risk is non‑negligible for environments where DFS is enabled and local users have relatively high permissions.
OpenCVE Enrichment