Impact
A null pointer dereference has been identified in Windows DirectX that can be triggered by a local, authorized attacker, resulting in a denial of service of the affected system. The flaw maps to CWE-476 and can cause an application or system crash without providing any unauthorized access or data disclosure.
Affected Systems
The vulnerability impacts Microsoft Windows 11 version 22H3, 23H2, 24H2, and 25H2, as well as Windows Server 2022 and 2025, including their Server Core and 23H2 edition deployments. Both x64 and ARM64 architectures are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of < 1% signals a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing urgency. Attack execution requires local or privileged access, meaning an attacker must already be authenticated or present on the machine for exploitation.
OpenCVE Enrichment