Impact
The Windows NTFS flaw is an out‑of‑bounds read that can be triggered by an attacker who already has authorized local access. The bug allows a process to read data that resides beyond the bounds of a buffer in the NTFS file system driver, which can enable the attacker to exfiltrate privileged memory contents or manipulate data to cause privileged code execution. The weakness is classified as CWE‑125 and represents a classic boundary‑checking defect that can directly lead to privilege escalation on the affected host.
Affected Systems
Microsoft operating systems released from Windows 10 Version 1607 through 22H2, Windows 11 up to 26H1 (including Arm64 and x64 builds), and Windows Server editions from 2012 up to 2025—including core installations—are known to contain the vulnerable NTFS driver. The vendor list in the CVE includes all these products, and the Microsoft security update referenced covers each of them.
Risk and Exploitability
The CVSS base score of 7.8 categorizes this vulnerability as high severity for local privilege escalation. The EPSS score is below 1%, indicating that it is not widely exploited at the time of writing, and it is not listed in the CISA KEV catalog. Exploitation requires that the attacker already has authenticated local access; however, once the vulnerability is leveraged, the attacker can elevate to system-level privileges, which presents a significant risk to confidentiality, integrity, and availability. The attack surface is limited to interactive or service accounts with local authority, and no network‑based trigger is required.
OpenCVE Enrichment