Impact
The vulnerability is a buffer over-read in the Windows Projected File System that allows an attacker who already has local access to read beyond the bounds of a buffer. This flaw can be abused by a local user to gain higher privileges and thereby compromise the confidentiality, integrity, or availability of the system. The weakness is a misuse of buffer size handling (CWE-126).
Affected Systems
The flaw affects Microsoft Windows operating systems including Windows 10 versions 1809, 21H2 and 22H2; Windows 11 versions 22H3, 23H2, 24H2, 25H2 and 26H1; as well as Windows Server editions 2019, 2022 and 2025, including their server core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. Exploitation requires a local, authorized attacker; the attack vector is inferred from the description as local privilege escalation rather than remote. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Overall, the risk is significant for systems that have not been patched, as a local user could elevate privileges to perform malicious actions.
OpenCVE Enrichment