Impact
The Virtual Hard Disk (VHD) Miniport Driver in certain Windows releases contains an out‑of‑bounds read that can be triggered by an authorized local user. By exploiting this flaw, an attacker can gain permissions beyond their current level, potentially taking full control of the system. The vulnerability is classified as CWE‑125 for memory safety failure and as CWE‑200 for information exposure, indicating that insufficient bounds checking allows a driver to read beyond allocated memory regions.
Affected Systems
Affected Windows products include Windows 10 Version 1809, 21H2, and 22H2 on both 32‑bit and 64‑bit platforms; Windows 11 Versions 23H2, 24H2, 25H2, and 26H1 on x64 and ARM64 architectures; and Windows Server 2019, 2022, 2025 in both full and Server Core installations.
Risk and Exploitability
The severity score of 7.0 on the CVSS scale indicates a high risk to confidentiality and integrity. An EPSS score is not available, so the current exploitation probability is unknown, but the local attack vector combined with the lack of mitigations suggests that an attacker who can create or manipulate a VHD file can potentially execute privileged code. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, however the impact remains significant if the flaw is successfully leveraged.
OpenCVE Enrichment