Impact
The flaw is an integer overflow or wraparound in the Windows Work Folder Service that permits an attacker with authorization to run code on the target system. The vulnerability can be leveraged to execute arbitrary code, compromising confidentiality, integrity, and availability of the affected machine. The weakness corresponds to CWE-190, which describes how numeric overflows can lead to unintended behavior.
Affected Systems
Microsoft Windows 10 Version 1607, Windows 10 Version 1809, Windows Server 2012 R2, Windows Server 2012 R2 (Server Core), Windows Server 2016, Windows Server 2016 (Server Core), Windows Server 2019, Windows Server 2019 (Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core). The products listed have been affected through the Windows Work Folder Service component.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity flaw, and the lack of an EPSS score indicates that current exploitation probability data is unavailable. The vulnerability is not currently in the CISA KEV catalog. A likely attack vector is a network‑based exploit that requires the attacker to have some level of authorization, such as a user account or administrative access, to the target system.
OpenCVE Enrichment