Impact
The vulnerability arises from improper validation of input consistency within Windows Secure Kernel Mode, allowing an authorized local user to elevate privileges. The flaw permits a local attacker, who already has a user-level account, to gain higher privilege rights without additional privileges, making it a local privilege escalation flaw. The weakness is classified as CWE-1288.
Affected Systems
Affected by the flaw are numerous Microsoft Windows desktop and server operating systems. The vulnerable versions include Windows 10 build 1607, 1809, 21H2, and 22H2; Windows 11 build 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 categorizes it as a high‑severity vulnerability, while the EPSS score of less than 1% indicates that exploit attempts are currently rare but not impossible. The flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit exists yet. The attack vector is inferred to be local; an attacker must run code on the target machine and is limited to a user‑level account that owns the code or has permission to execute it. If exploited, the attacker could gain elevated privileges, potentially compromising system integrity and confidentiality.
OpenCVE Enrichment