Impact
Improper link resolution before file access in the Windows Container Isolation FS Filter Driver, unionfs.sys, enables an attacker with local authorization to alter files. This flaw can be exploited to modify or replace files that the container isolation mechanism protects, potentially compromising container integrity or persistence of malicious code.
Affected Systems
Microsoft Windows 11 version 26H1 is affected. Containers running on this OS that rely on the unionfs.sys filter driver are vulnerable if the OS is at this release level.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate risk. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires local, authorized access to the system, meaning the threat level is limited to environments where privileged users or compromised local software can leverage the flaw to tamper with container files.
OpenCVE Enrichment