Impact
The vulnerability is a heap-based buffer overflow in the Windows Volume Manager Extension Driver, as identified by CWE‑122. An attacker with local access to the affected system can invoke the overflow, resulting in an elevation of privileges to the level of the driver. The flaw enables the attacker to run code with elevated privileges, potentially allowing full control over the machine.
Affected Systems
Affected systems are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. The issue spans both x86, x64, and arm64 architectures as indicated in the associated CPE entries.
Risk and Exploitability
The CVSS score of 7 indicates a high severity impact. EPSS is not available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is local; an authorized attacker must have access to the machine to trigger the heap overflow. Once exploited, the attacker can gain escalated privileges, compromising confidentiality, integrity, and availability of the local system.
OpenCVE Enrichment