Impact
The vulnerability is a heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver. An authorized attacker can exploit this flaw by supplying crafted input that overflows a heap buffer, thereby allowing privilege escalation on the local system.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate severity. Because no EPSS score is available and the vulnerability is not listed in CISA KEV, the likelihood of public exploitation is presently unknown. The flaw requires local, authorized execution; an attacker who is already running as a user on the machine can invoke the vulnerable driver routine to achieve privilege escalation, potentially giving them full control of the host.
OpenCVE Enrichment