Impact
The vulnerability is an out‑of‑bounds read in the Windows Projected File System component. An attacker who already has local access can exploit this flaw to gain elevated privileges on the affected machine. The weakness, classified as CWE‑125, permits reading memory beyond allocated buffers, which can be leveraged to modify execution flow and obtain higher authority than originally granted.
Affected Systems
The flaw affects multiple Microsoft Windows releases, including Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 22H3, 23H2, 24H2, and 25H2; and Windows Server editions 2019, 2022 (and 23H2 Edition Server Core), as well as Windows Server 2025 (both standard and Server Core). The affected builds support both x86 and x64 architectures, with select ARM64 variants listed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 percent suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not currently listed in CISA KEV. Exploitation requires an attacker with local authority; a local user or service running with limited rights could trigger the out‑of‑bounds access to elevate privileges.
OpenCVE Enrichment