Impact
The vulnerability is an improper access control flaw in the Windows Projected File System that permits an authorized local user to elevate privileges on the affected system. This weakness, identified as CWE-284, could allow the attacker to execute code with higher privileges, potentially compromising system integrity and confidentiality. The impact is confined to local privilege escalation, as the attacker must already be authenticated to the system.
Affected Systems
The flaw affects a range of Microsoft Windows operating systems, including Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 22H3, and 26H1; and Windows Server editions 2019, 2022, 2025, as well as their Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. Exploitation requires local access and an already authenticated user, making the attack vector local. If such conditions exist, the vulnerability could be exploited to gain elevated privileges on the system.
OpenCVE Enrichment