Impact
A heap-based buffer overflow exists in the Windows Work Folders component that allows a local, authorized user to gain elevated privileges on the affected system. The vulnerability leads to a change in the integrity of the Windows kernel and may grant the attacker additional rights above those originally possessed.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Microsoft Windows 11 versions 24H2, 25H2, and 26H1 are impacted. The affected builds include x86, x64, and ARM64 architectures as applicable.
Risk and Exploitability
The CVSS score is 7.8, indicating considerable severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The vulnerability requires local authorization; an attacker must already have user access to the machine to trigger the buffer overflow. No public exploit has been reported, and the attack vector is inferred to be local due to the nature of the vulnerability and lack of remote exploitation information.
OpenCVE Enrichment