Impact
Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. The flaw, identified as CWE‑822, could be exploited by a user who can trigger the vulnerable code, potentially allowing them to assume higher privileges and compromise system integrity or confidentiality.
Affected Systems
Affected Microsoft products include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 22H3, 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, and the 23H2 Server Edition. All listed builds, whether 32‑bit or 64‑bit, as well as Server Core installations for the server editions, are impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. No EPSS score is available, and it is not currently listed in the CISA KEV catalog. The likely attack vector is local; an attacker who can execute code on the machine can exploit the dereference to gain elevated privileges. Consequently, systems should treat this as a significant local risk until a patch is applied.
OpenCVE Enrichment