Impact
The flaw is an integer underflow that allows an attacker to execute arbitrary code when Windows Performance Monitor processes crafted data. The vulnerability can be triggered by an unauthorized user over a network, giving the attacker the ability to run code with the privileges of the monitoring service. This constitutes a serious breach of confidentiality, integrity, and availability, and is classified as a high‑severity remote code execution flaw.
Affected Systems
Microsoft Windows 11 in the 23H2, 24H2, 25H2, and 26H1 releases—including arm64 and x64 editions—and Microsoft Windows Server 2022 and 2025 (including Server Core installations) are affected.
Risk and Exploitability
The CVSS score of 8.1 indicates a high impact. EPSS data is not available, so the current exploit probability is unknown, but the vulnerability is not listed in the CISA KEV catalog. The likely attack path is a network connection to the Performance Monitor service on a vulnerable system, with the attacker exploiting an integer wrap‑around to gain code execution. No additional exploitation prerequisites are mentioned in the data provided.
OpenCVE Enrichment