Impact
A heap‑based buffer overflow in the Windows DWM Core Library allows an authorized attacker to elevate privileges locally. The flaw can enable a non‑privileged user to acquire higher privileges on the host machine. The vulnerability is classified as CWE‑122, CWE‑20, and CWE‑416.
Affected Systems
Affected releases are Microsoft Windows 11 26H1 for both x64 and arm64 architectures. No other operating systems or product families are listed as impacted by this flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation. The EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The flaw is local, requiring an authenticated attacker already on the machine. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment