Impact
The vulnerability is a buffer over-read in the Windows Volume Manager Extension Driver, enabling an authorized local user to read beyond intended memory boundaries and manipulate driver behavior. This flaw permits the attacker to gain higher privileges on the affected system by exploiting the driver’s internal calculations, allowing the execution of code with administrative rights and the potential to bypass security controls.
Affected Systems
Affected are multiple Windows releases: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 (both standard and Server Core installations). The CPE strings confirm these products are impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score of < 1% suggests a very low probability of exploitation in observed environments. The vulnerability is not listed in CISA’s KEV catalog, and no active exploits are documented. It is inferred that the attack requires a local, authorized user with access to the system and the ability to provide crafted input to the Volume Manager Extension Driver. Successful exploitation would enable the attacker to execute arbitrary code with elevated privileges.
OpenCVE Enrichment