Impact
This vulnerability is a heap‑based buffer overflow in the Windows NTFS file system. An authorized local user can exploit a failure in bounds checking when the file system parses certain input, allowing the attacker to execute arbitrary code with SYSTEM privileges. The flaw can be used to modify or delete protected files, install malware, or otherwise change the operation of the operating system, compromising confidentiality, integrity, and availability at the host level.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their core installations. Any of these systems running the unpatched NTFS driver are vulnerable.
Risk and Exploitability
The CVSS score is 7.8, indicating a high severity local privilege escalation. No EPSS score is listed, but the CVE is not in the CISA KEV catalog, so the likelihood of exploitation in the wild is unclear. Because the attack requires local privileges and can be triggered by crafted data processed by NTFS, the risk is significant for any system where users can write to the affected volumes. An attacker could abuse this flaw to gain full control of the machine.
OpenCVE Enrichment