Impact
The vulnerability is an out‑of‑bounds read in the Virtual Hard Disk (VHD) Miniport Driver. An authenticated local user can exploit improper bounds checking to read memory outside the intended buffer, enabling code execution or manipulation of system state with elevated privileges. This flaw corresponds to CWE‑125 and can allow an attacker to bypass access controls and gain higher than intended rights.
Affected Systems
Affected systems are Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 releases 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 in both full and Server Core editions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk, but the EPSS score is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known active exploitation yet. However, the requirement of an authorized local user means that any device where an attacker can gain local access could be affected. The likely attack vector is local, implying mitigation should focus on preventing local compromised accounts from accessing VHDs.
OpenCVE Enrichment