Impact
Improper link resolution before file access in Windows NTFS allows an authorized local attacker to tamper with files. The flaw occurs when the kernel resolves NTFS paths, incorrectly following symbolic or reparse‐points links, enabling the attacker to modify or replace target files that should not be accessible. This results in unintended file alterations but does not provide remote code execution or credential escalation.
Affected Systems
Affected systems include Windows 11 operating systems released in the 23H2, 24H2, 25H2, and 26H1 update cycles, across both arm64 and x64 architectures. The vulnerability applies to the NTFS filesystem component on these versions.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity, and no EPSS score is available, with the vulnerability not currently listed in the CISA KEV catalog. Exploitation requires an authenticated user with write access to the target directory; a local attacker can exercise the flaw by crafting a path that forces the system to follow a malicious link. Because the attack vector is local and privilege‑dependent, the risk is limited to the compromised account, but it could still allow modification of critical system files if permission boundaries are not enforced.
OpenCVE Enrichment