Impact
The Windows StateRepository API manages file access operations and its access control granularity is insufficient. A local user who already has some level of access can exploit this flaw, as reflected in CWE-285 (Improper Access Control) and CWE-1220 (File and Directory Permissions Misconfiguration).
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019 (including Server Core installation), Windows Server 2022, and Windows Server 2025 (including Server Core installation).
Risk and Exploitability
The CVSS score of 7.8 and an EPSS score of 3% indicate a moderate probability of exploitation. The vulnerability is not listed in CISA’s KEV catalogue, suggesting no confirmed exploits are publicly known. Based on the description, the attack scenario requires an authenticated local user; the attacker can elevate privileges to system level without additional credentials. This could enable full control over the affected operating system versions.
OpenCVE Enrichment