Impact
A protection mechanism failure in the MSHTML framework lets an attacker bypass a built‑in security feature when content is received over a network. The flaw, classified as a security misconfiguration (CWE‑693), can allow malicious data to be processed by the component without the intended safeguards, potentially compromising the confidentiality or integrity of the processed information.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, 22H2; Windows 11 22H3, 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and the 23H2 edition. All processor architectures (x86, x64, arm64) and Server‑core installations are included.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of 15 % points to a significant likelihood of exploitation. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog, confirming that real‑world exploitation has occurred. Based on the description, it is inferred that the likely attack vector is a network‑based delivery of malicious content that causes the MSHTML component to process it; the flaw does not require local privileges.
OpenCVE Enrichment