Impact
Integer overflow or wraparound in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. The flaw enables local privilege escalation, enabling the attacker to execute operations with elevated permissions, reflecting the classic integer over/underflow weakness (CWE‑190).
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2; Windows 11 releases 23H2, 24H2, 25H2 and 26H1; Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025 – including Server Core installations – are affected.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability has a CVSS v3.1 score of 7.8, indicating high severity for a local privilege escalation. The EPSS score is reported as less than 1%, showing a low but non-zero probability of exploitation. Because the flaw requires authorized local access, it remains a realistic risk in environments where privileged accounts are not tightly controlled, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment