Impact
An out‑of‑bounds read bug in the Windows NTFS file system allows an authorized local user to read data beyond the intended memory bounds, potentially exposing sensitive information stored on the volume. The flaw is classified as CWE‑125 and provides local information disclosure without privilege escalation or remote access.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 releases 23H2 through 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (server core included). All affected builds are listed in the update guide as needing remediation.
Risk and Exploitability
With a CVSS score of 5.5 the vulnerability sits in the medium range and is not tracked in the CISA KEV catalog. The EPSS score is listed as < 1 %, indicating a very low exploitation probability. The vulnerability requires an authorized local user to trigger the out‑of‑bounds read; therefore the attack vector is local. Based on the description, it is inferred that the attacker would need to invoke an operation that causes the NTFS driver to read beyond allocated buffers, potentially leaking memory content. No public exploits are currently available; however, the limited EPSS score reflects the low likelihood of widespread exploitation. Users with local privileges remain the impacted group.
OpenCVE Enrichment