Impact
A heap-based buffer overflow in Windows Volume Shadow Copy can allow an attacker with physical access to gain elevated privileges on the affected system. This flaw permits the escalation from a regular user to an administrator, giving the attacker complete control over the machine and the ability to execute arbitrary code. The vulnerability is categorized as CWE-122, a Classic Heap-based Buffer Overflow.
Affected Systems
The affected releases include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012 (and Core installations), 2012 R2, 2016, 2019, 2022, and 2025 (including Core installations).
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score is not available, making it difficult to gauge current exploitation likelihood. Because the exploit requires physical access to the device to trigger the heap overflow in Volume Shadow Copy, the attack vector is local. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread or publicly documented exploitation as of this analysis. Nonetheless, the impact of privilege escalation warrants prompt remediation on all affected systems.
OpenCVE Enrichment