Impact
This vulnerability is a heap-based buffer overflow in the Windows Compressed Folder component. The overflow can be triggered by a maliciously crafted compressed folder that an attacker can deliver over a network. Successful exploitation would allow the attacker to execute arbitrary code with the privileges of the local user, potentially compromising the entire system, affecting confidentiality, integrity, and availability.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2012 through 2025 (including Server Core installations). These encompass the listed CPE strings for both x86 and x64 architectures.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical, indicating that exploitation could yield complete system compromise. The EPSS score of 0.00996 indicates a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based, inferred from the description that an unauthorized attacker can trigger the overflow over a network.
OpenCVE Enrichment