Impact
A heap-based buffer overflow exists in the Windows Encrypting File System (EFS) component, allowing an attacker who is already authorized on the network to gain elevated privileges. The vulnerability is introduced during memory handling within EFS, and its exploitation can lead to execution of arbitrary code with higher privileges, compromising confidentiality, integrity, and availability of the affected system. The cited weakness corresponds to a classic buffer overflow (CWE-122).
Affected Systems
Affected Microsoft environments include Windows 10 versions starting with 1607, including 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server releases such as 2012, 2012 R2, 2016, 2019, 2022, and 2025, with core installations listed where applicable. All listed operating systems may be impacted if they have not applied the relevant security update.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, suggesting a significant potential impact if exploited. The EPSS score is not available, but the lack of a current EPSS entry does not negate the risk; the advisory does not list it in CISA’s KEV catalog, so it is not confirmed as a known exploited vulnerability in the wild. Attack likely requires an attacker to be authenticated and have access to the network, suggesting that privilege escalation could be achieved in corporate or remote settings where EFS is enabled. Given the high severity and the absence of a widespread exploit record, organizations should treat this as a priority for patching.
OpenCVE Enrichment