Impact
The vulnerability is an integer overflow within the WinFsp filesystem driver. When the integer value is corrupted, the driver can be manipulated to perform privileged operations, effectively granting an attacker system-level access to the affected software.
Affected Systems
The affected product is WinFsp. Any installed version that is not the latest release is potentially impacted. The advisory does not specify particular sub‑versions, but the recommendation is to upgrade to the most recent release.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1% indicates a very low but nonzero chance of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the nature of WinFsp, a likely vector involves manipulating malicious filesystem operations. An attacker would need to craft input data that triggers the integer overflow in the vulnerable function.
OpenCVE Enrichment