Impact
The vulnerability is a heap‑based buffer overflow in the NTFS file system module. An attacker who tricks NTFS into processing a specially crafted file can execute arbitrary code with the privileges of the system account, compromising confidentiality, integrity, and availability on the affected machine. The flaw is a classic unbounded write in heap memory that can be exploited to alter program behavior or inject malicious logic. This type of weakness is listed as CWE-122.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations, are all enumerated as affected by this flaw.
Risk and Exploitability
The CVSS score of 6.8 indicates a high risk of moderate impact should the flaw be successfully exploited. The EPSS value is currently not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. Based on the description, the likely attack vector requires an attacker to deliver a malicious file to the target system, which is most feasible through physical access or via a compromised local user account. While remote exploitation is not explicitly stated, any pathway that allows an attacker to place a crafted NTFS file on the host could potentially trigger the flaw.
OpenCVE Enrichment