Impact
A heap-based buffer overflow exists in the Windows NTFS file system, enabling an attacker to execute arbitrary code by exploiting how the kernel handles certain file system metadata structures. The flaw can be triggered only when the attacker has physical access to the machine, making it a local privilege escalation vector. Once exploited, the attacker gains code execution at the kernel level, which can lead to full system compromise.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core deployments.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate impact severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. Given that a physical attack is required, the exploitability window is narrower than for remote attacks, but the local code execution capability still poses a significant risk to affected systems.
OpenCVE Enrichment