Impact
The vulnerability is an out-of-bounds read (CWE-125) in the Windows NTFS file system that allows an unauthorized local attacker to elevate privileges. This grants the attacker higher system rights on the compromised machine.
Affected Systems
Affected systems include Microsoft Windows 10 from 1607 through 22H2, Windows 11 from 23H2 through 26H1, and Windows Server 2012 up to Windows Server 2025, covering both Server Core and full installs. The CVE impacts systems running NTFS on these versions, regardless of CPU architecture segments noted in the CPEs (x86, x64, arm64).
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of <1% suggests a low but nonzero likelihood of exploitation. As a local privilege‑escalation flaw that is not listed in the CISA KEV catalog, any user with sufficient local file system access can attempt the exploit, but there are currently no known documented attacks.
OpenCVE Enrichment