Impact
A heap‑based buffer overflow in the Volume Manager Driver allows an attacker with local access to gain higher privileges on the affected Windows systems. The vulnerability, classified as CWE-122, could let the attacker execute arbitrary code under an elevated security context, potentially compromising system integrity and confidentiality. The impact is limited to the host where the attack occurs, and exploitation requires that the attacker be authorized to run locally.
Affected Systems
The flaw affects multiple Microsoft Windows releases. It is present in Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including their Server Core installations. The specific builds are enumerated in the CNA vendor/product list.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity and the attack vector is local, requiring the attacker to be authenticated and already have some local privileges. The EPSS score is unavailable, and the vulnerability is not listed in CISA KEV, suggesting no widespread active exploitation yet. Nonetheless, given the local privilege escalation potential, the risk remains significant for systems with exposed local accounts or unmanaged users.
OpenCVE Enrichment