Impact
A heap‑based buffer overflow in the Windows Universal Disk Format File System Driver (UDFS) allows an authorized local attacker to gain higher privileges. The flaw is listed as CWE‑122 and permits uncontrolled overwriting of memory during the handling of UDFS file system data, leading to privilege escalation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating moderate‑to‑high severity for a local attacker with authorization. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the local impact remains significant. An attacker who can execute code on the affected systems could exploit the overflow to elevate privileges, compromising confidentiality, integrity, and availability of the host. No remote exploitation vector is disclosed, and the attack requires the presence of the UDFS driver and the ability to interact with it locally.
OpenCVE Enrichment