Impact
A heap‑based buffer overflow (CWE-122) exists in the Windows VOLSNAP.SYS driver that allows an authorized attacker to execute arbitrary code locally. The vulnerability arises from memory corruption caused by unvalidated input in the driver. Based on the description, it is inferred that the code executed runs with the privileges of the current user context.
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. The specific kernel driver cited, VOLSNAP.SYS, is present on both desktop and server editions of these operating systems.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. Exploitation requires local, authorized access to the target system; the vulnerability cannot be triggered remotely. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation may be limited at this time. Based on the description, it is inferred that code execution could enable privilege escalation or affect system integrity.
OpenCVE Enrichment