Impact
An out‑of‑bounds read in the Windows DWM Core Library enables a locally authenticated attacker to elevate privileges on the target machine by manipulating buffer underruns that allow unauthorized memory access. The flaw can be exploited by a user with authorized access to gain higher privileges, potentially leading to full system compromise. This vulnerability is classified as CWE‑125, highlighting a buffer underrun that can lead to privilege escalation rather than simple information disclosure.
Affected Systems
The vulnerability affects Windows 11 version 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation. All versions are referenced by Microsoft in the advisory, indicating that any copy of these releases is potentially exposed.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact. The EPSS score is 0.388%, reflecting a low probability of exploitation in the wild but not eliminating the possibility of malicious use. The vulnerability is not listed in CISA KEV catalog, suggesting no known active exploitation. The attack vector is local; an attacker must have user or elevated privileges on the target machine to trigger the read. The flaw can be exploited by a locally authenticated user who can manipulate a buffer underrun in the DWM Core Library to read protected memory, potentially leading to privilege escalation.
OpenCVE Enrichment