Impact
A null pointer dereference in the Windows Performance Counters module allows an attacker with local system access to gain elevated privileges. The vulnerability is categorized as a Null Pointer Dereference (CWE‑476) and can be exploited by an authorized user to execute code with higher privileges on the affected machine.
Affected Systems
Affected are Microsoft Windows 10 and 11 builds ranging from version 1607 and 1809 up through 25H2 and 26H1, as well as Windows Server 2012 to Windows Server 2025, including all server core installations. Systems running any of these releases on either x86, x64, or arm64 architectures are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, and the attack vector is presumably local; an attacker must be able to log in or otherwise operate on the affected system to leverage the null reference for privilege escalation.
OpenCVE Enrichment