Impact
The vulnerability is an integer overflow or wraparound in Windows Performance Monitor that allows an unauthorized attacker to execute code over a network. An attacker can send crafted input that triggers the flaw, causing the monitor to run malicious code with the service’s privileges, enabling remote code execution without requiring local authentication.
Affected Systems
The flaw impacts Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2022 and Windows Server 2025 installations, on both x64 and arm64 architectures, as delineated by the affected CPE entries.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as Severe, and the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation. Authentication is not required; an attacker can trigger the flaw by sending crafted data to the Performance Monitor service over a network, potentially enabling execution of attacker-supplied code. The threat remains significant for any host exposed to the service, especially if the service is publicly reachable.
OpenCVE Enrichment