Impact
The vulnerability is a heap‑based buffer overflow in the Windows NTFS file system. An attacker with the ability to write to NTFS metadata can trigger the overflow and execute arbitrary code on the target machine. The weakness is a classic heap overflow (CWE‑122). This flaw allows the attacker to gain code execution on the local machine, but there is no evidence of a remote exploitation vector without local privileges or user interaction.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations). These include both x86 and x64 platforms as listed in the vendor docket, covering a broad range of recent Windows releases.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity weakness. EPSS is currently not available, so the likelihood of automated exploitation is unclear, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw requires local or authorized access to modify NTFS metadata, the attack surface is limited to contexts where an attacker can place files on the target system. The vulnerability can be leveraged after the attacker obtains local user or system privileges, after which they could run arbitrary code, Hijack processes, or persist on the system. The absence of a remote vector reduces the overall risk compared to a purely remote exploit, but the impact remains significant for any user with write access to the affected NTFS volume.
OpenCVE Enrichment