Impact
Improper authentication in Windows Cryptographic Services permits an attacker with local access to gain elevated privileges. By bypassing the usual authentication checks, the attacker can run code with higher rights, potentially compromising system integrity, confidentiality, and availability. The weakness is defined as CWE-287, reflecting improper authentication.
Affected Systems
Affected Windows products include Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core).
Risk and Exploitability
The vulnerability carries a CVSS score of 8.4 and is not listed in the CISA KEV catalog; EPSS information is not currently available. Because it is a local escalation flaw, the attack vector is likely local. The high severity rating indicates that any local attacker could exploit it, emphasizing the need for timely remediation and monitoring for elevated privilege attempts.
OpenCVE Enrichment