Impact
The CVE description indicates that an integer overflow or wraparound in the Windows NT OS Kernel allows an authorized attacker to elevate privileges locally. This represents a classic integer overflow flaw (CWE-190) that can enable local privilege escalation.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2; Windows 11 releases 23H2, 24H2, 25H2 and 26H1; Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025 – including Server Core installations – are affected.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability has a CVSS v3.1 score of 7.8, indicating high severity for a local privilege escalation. The EPSS score is reported as less than 1%, showing a low but non-zero probability of exploitation. Because the flaw requires authorized local access, it remains a realistic risk in environments where privileged accounts are not tightly controlled, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment