Impact
The description states that a heap‑based buffer overflow in the Windows Kernel allows an authorized attacker to elevate privileges locally. This overflow is a classic buffer overflow weakness (CWE‑122) and may also involve a use‑after‑free condition (CWE‑416). The resulting privilege escalation can compromise confidentiality, integrity, and availability on the host.
Affected Systems
Affected releases include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and the corresponding Server Core installations.
Risk and Exploitability
The CVSS score of the vulnerability is 7, placing it in the high‑severity range. The EPSS score of <1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The likely attack vector is an authenticated local user exploiting the heap‑based buffer overflow, though the updated description does not confirm the exact path.
OpenCVE Enrichment