Impact
The flaw is a heap‑based buffer overflow in the Windows DNS client. An authorized victim can trigger the overflow to corrupt memory, allowing the execution of arbitrary code with elevated local privileges. The weakness is categorized as CWE‑122.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025, including Server Core installations.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is considered high severity. The EPSS score of less than 1 % indicates a very low probability of active exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is local: an attacker with user privileges who can run code on the affected system must trigger the overflow, so the risk is confined to local users rather than remote actors.
OpenCVE Enrichment