Impact
The flaw is a heap‑based buffer overflow in Windows Cryptographic Services that can be triggered by an authorized local user. Exploitation of the overflow allows the attacker to gain higher privileges on the same system, potentially running code with elevated rights.
Affected Systems
Affected Windows products include Windows 10 v1607, v1809, v21H2, v22H2 and Windows 11 v23H2, v24H2, v25H2, 22H3, 26H1. Server editions impacted are Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and 23H2.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate to high severity local privilege escalation. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need local access and the ability to trigger the overflow; the vulnerability cannot be exploited remotely.
OpenCVE Enrichment