Impact
The vulnerability is a heap‑based buffer overflow within the Windows NTFS file system driver. When a crafted or malformed NTFS operation is processed, the driver fails to enforce proper bounds checking on a heap object, allowing an attacker’s payload to overwrite control data. The result is execution of arbitrary code in the context of the user that initiates the operation. This flaw is not tied to privileged code paths, so an unprivileged local user can trigger it. The 8.4 CVSS score highlights the severity of the flaw, reflecting the potential impact on confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2 through 26H2 (including 24H2, 25H2, and 26H1), and Windows Server releases from 2012 through 2025 – including both full installations and Server‑Core configurations – are all affected. The NTFS driver is shared across these platforms, meaning the vulnerability spans the majority of contemporary Windows desktops, laptops, and servers.
Risk and Exploitability
Exploitability is limited to a local context; the attacker only needs local access to the system to trigger the heap corruption. No remote network trigger has been documented, and the EPSS score of <1% indicates a very low probability of exploitation. The flaw is not currently listed in the CISA KEV catalog, but the high CVSS rating and widespread affected stockpile make it a priority. The absence of a publicly published exploit does not lessen the risk; building a local unit test is likely straightforward given the clear overflow description.
OpenCVE Enrichment