Impact
Heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver can allow an attacker with network access to the target machine to elevate privileges. The flaw permits out‑of‑bounds writes to heap memory, potentially leading to arbitrary code execution under a higher privilege level. If exploited, the attacker could gain administrative rights on the affected system.
Affected Systems
Affected systems include Microsoft Windows 10 (builds 1607, 1809, 21H2, and 22H2), Windows 11 (builds 23H2, 24H2, 25H2, and 26H1), and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, with or without Core installations.
Risk and Exploitability
The CVSS score of 8 indicates high severity, though the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network‑based, requiring the attacker to be on the same network segment or to have otherwise authorized access. Given the lack of publicly reported exploitation, the immediate risk depends on internal exposure and network segmentation, but the high CVSS suggests significant potential impact if the flaw is leveraged.
OpenCVE Enrichment