Impact
Improper privilege management in the Connected User Experiences and Telemetry service allows an authorized local attacker to stop the service, causing a denial of service for the impacted user. This weakness stems from incorrect handling of system privileges, which can prevent the service from functioning normally.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 22H3, 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025. Those editions are listed as affected in Microsoft advisory references.
Risk and Exploitability
With a CVSS score of 5.5 the issue is of moderate severity, and the attack relies on local authorized privileges, limiting the attacker to systems where credentials exist. No exploit probability score is available and the vulnerability is not listed in the CISA KEV catalog, indicating it is not a widely exploited threat at present.
OpenCVE Enrichment