Impact
Untrusted pointer dereference in the Windows Universal Plug and Play Device Host enables a user with local access to elevate privileges. The flaw allows exploitation that results in code execution with system privileges, compromising confidentiality, integrity, and availability on the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 22H3 and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and 23H2 editions including core installs.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation vulnerability. The absence of an EPSS score and lack of listing in the CISA KEV catalog suggest limited current exploitation activity, yet the local nature of the flaw means an authorized user can readily elevate privileges once the vulnerability exists.
OpenCVE Enrichment