Impact
Improper restriction of name handling for files and other resources within Active Directory Domain Services allows an attacker who already has authenticated access to the domain to create or modify objects with names that bypass built‑in controls, resulting in an elevation of privilege over the network.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 22H3, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 are impacted. Domain controllers, member servers, and client machines running any of these editions are vulnerable, and the flaw applies to accounts that possess domain-level privileges.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity, while the EPSS score of 1% suggests a currently low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no active, publicly disclosed exploitation. Based on the description, it is inferred that an attacker would need compromised credentials with domain rights and the ability to manipulate AD objects over the network to profit from this flaw.
OpenCVE Enrichment