Impact
This vulnerability is an out‑of‑bounds read in the exFAT file system driver that permits an attacker who can attach an exFAT volume to a Windows system to obtain higher privileges. The flaw is classified as CWE‑125. The description makes no claim of data leakage or arbitrary code execution; the primary consequence is the escalation of privilege within the local system context.
Affected Systems
Affected systems include Microsoft Windows 10 version 1607 through 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025. All these releases ship the exFAT file system driver and are listed as vulnerable in the Microsoft advisories.
Risk and Exploitability
The CVSS score of 8 indicates a high severity. The EPSS score is not available, so the exploitation probability cannot be quantitatively assessed, and the vulnerability does not appear in the CISA KEV catalog. The likely attack vector is network‑based, where an attacker who can present a malicious exFAT volume to a Windows machine—such as through a remote share or network file transfer—can trigger the out‑of‑bounds read and raise their privileges on that machine. No public exploits are known at this time.
OpenCVE Enrichment