Impact
The flaw is a heap‑based buffer overflow in the Windows DWM Core Library. An authorized user on a Windows 11 26H1 system can exploit the vulnerability to elevate privileges locally, potentially gaining elevated administrative rights. The weakness is identified by CWE‑122, CWE‑20, and CWE‑416.
Affected Systems
Affected releases are Microsoft Windows 11 26H1 for both x64 and arm64 architectures. No other operating systems or product families are listed as impacted by this flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation. The EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild. The flaw is local, requiring an authenticated attacker already on the machine. It is not listed in the CISA KEV catalog.
OpenCVE Enrichment