Impact
An out‑of‑bounds read in the Windows NTFS file system allows a local attacker with existing authorized access to elevate privileges. The flaw, identified as CWE‑125, can be used to bypass security controls and run code with higher privileges, potentially giving access to protected resources. No network boundary is required, and exploitation requires that the attacker already has a user account on the target machine.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022, and 2025 (including Server Core). All builds listed in the Microsoft catalog are impacted.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity. Exploit probability data is not available and the vulnerability is not listed in CISA's KEV catalog. The attack vector is local and requires that the attacker be authorized on the machine; under those conditions the attacker can elevate privileges.
OpenCVE Enrichment