Impact
Windows NTFS contains an out‑of‑bounds read that allows an attacker with authorized access to read data that should be outside the intended bounds of the NTFS structure. The affected code can leak arbitrary content from the volume, leading to disclosure of sensitive information. This weakness is classified as CWE‑125, an unchecked read that violates confidentiality.
Affected Systems
The vulnerability affects several Microsoft Windows operating systems. On Windows 10 it applies to version 1809, 21H2, and 22H2. In Windows 11, the affected releases are 23H2, 24H2, 25H2, and 26H1. On server platforms the flaw exists in Windows Server 2019, Windows Server 2022, Windows Server 2025, and their Server Core installations. All affected systems must be evaluated for remediation.
Risk and Exploitability
The CVSS Base score of 5.7 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation. The attacker must be authorized on the system or have access to network shares to exercise the read. Because the vulnerability is local or requires local share access, it is less likely to be exploited remotely at scale. Nonetheless, the potential for information disclosure mandates prompt patching.
OpenCVE Enrichment