Impact
A heap-based buffer overflow in the Virtual Hard Disk (VHD) Miniport Driver permits an attacker with local privilege to execute arbitrary code on the affected system. The vulnerability stems from improper bounds checking during heap allocations, allowing overwrite of internal structures. Successful exploitation would enable the attacker to run code with the privileges of the user context that loaded the driver, potentially escalating within the local environment.
Affected Systems
The flaw affects multiple Microsoft operating systems including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions such as 2012, 2012 R2, 2016, 2019, 2022 and 2025. The issue resides in the VHD miniport driver present in both client and server builds, as indicated by the associated CPE entries.
Risk and Exploitability
The CVSS score of 7.5 indicates significant severity, though the vulnerability is not listed in the CISA KEV catalog and the EPSS score is currently unavailable. The attack requires local execution and an authorized context, implying that a malicious user who has logged on or has access to the machine may exploit the flaw. Once executed, the attacker could potentially run code with the same privileges as the driver context, leading to privilege escalation or complete system compromise within the local scope.
OpenCVE Enrichment