Impact
A stack‑based buffer overflow located in the Windows Storage Management Provider allows a local attacker who already has user‑level access to gain elevated privileges. The vulnerability results from improper handling of inputs that overflow a stack buffer, leading to arbitrary code execution with higher privileges. As a result, an attacker could potentially gain administrator rights on the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 (versions 21H2 and 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, and 26H1), and Microsoft Windows Server 2022 and Windows Server 2025, including Server Core installations. The affected architectures include x86, x64, and arm64 as reflected in the supplied CPE data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk profile for local privilege escalation. Because exfoliating data is unavailable, the EPSS score cannot inform immediate likelihood of exploitation, but the lack of a KEV listing does not diminish the significance of the flaw. The attack requires only local execution and an authorized user, meaning it does not necessitate remote access or network exposure. While no public exploit is documented, the combination of a stack‑overflow and high severity makes the vulnerability a priority for mitigation.
OpenCVE Enrichment