Impact
A use‑after‑free flaw in Windows NTFS causes a locally‑authorized attacker, usually a user with standard permissions, to execute code in a privileged context. The vulnerability allows escalation to SYSTEM or another high‑privilege account, leading to unrestricted modification of system files, installation of malicious software, or persistence mechanisms. It is a classic memory‑management error (CWE‑416).
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1) as well as Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. These include both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates medium‑to‑high severity; EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The flaw is local and requires an authorized user to craft a malicious NTFS file or manipulate filesystem metadata. Consequently, the exploit is feasible in environments where users have write access to the target partition or where specific NTFS features are enabled, but it cannot be leveraged over the network by an unauthenticated attacker.
OpenCVE Enrichment