Impact
The flaw is a stack‑based buffer overflow in the Windows NTFS driver that can be triggered by an unauthenticated network attacker. By sending a specially crafted request, an attacker can overwrite return addresses on the stack and execute arbitrary code. The flaw is classified as CWE‑121, indicating that untrusted input writes beyond an array boundary, giving the attacker the ability to gain code execution with the privileges of the NTFS service running under the SYSTEM account. This could allow full compromise of the host and pivot to other network resources.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607 through 22H2, Windows 11 releases 23H2 through 26H1, and a range of Windows Server editions from 2012 to 2025, including both regular and Server Core installations. It impacts x86, x64, and ARM64 architectures and is present on all network‑exposed components that expose NTFS metadata over SMB or related protocols.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS score is unavailable, suggesting no public exploitation data yet. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote network traffic, specifically SMB or other NTFS‑wrapped protocols. Exploitation requires only unauthenticated access to the target machine and does not depend on elevated privileges, making the risk significant for exposed machines.
OpenCVE Enrichment