Impact
An attacker can trigger a heap‑based buffer overflow in the Windows NTFS file system. By sending crafted metadata or data over the network, an unauthenticated user may cause a buffer overrun that results in arbitrary code execution. The flaw allows the attacker to run code with the privileges of the Windows service that processes NTFS data, potentially giving full control of the operating system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and all corresponding Server releases of Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical. EPSS score is below 1% (approximately 0.00928), indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Inference from the description indicates the attack vector is network‑based, likely through SMB or other NTFS share protocols, allowing an unauthorized host to deliver malicious data. If exploited, the attacker could gain system‑level access and compromise the confidentiality, integrity, and availability of the affected machine.
OpenCVE Enrichment