Impact
Buffer over-read in the Windows Encrypting File System (EFS) allows a local user with authorized access to read beyond intended buffer boundaries and disclose information stored on the system. The vulnerability primarily enables extraction of sensitive data that should be protected by EFS encryption, resulting in confidentiality compromise for files and possibly related metadata. It is a classic information disclosure flaw classified as CWE-126.
Affected Systems
Microsoft Windows operating systems from Windows 10 version 1607 through Windows 11 version 26H1 and from Windows Server 2016 to Windows Server 2025 are affected. The vulnerability spans multiple release branches, including Server Core installations, and applies to both 32‑bit and 64‑bit builds, as well as ARM64 architectures for the newer Windows 11 releases.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate threat level, but the issue is only exploitable by an attacker who already has local authorized access to the target machine. EPSS information is unavailable, and the flaw is not listed in CISA’s KEV catalog. Because it relies on a local presence, remote exploitation is unlikely. Nonetheless, any user who holds encryption privileges could potentially leverage the over‑read to gather information that should remain protected by EFS. The remaining risk depends on the presence of high‑privilege accounts and the sensitivity of data encrypted with EFS.
OpenCVE Enrichment