Impact
The vulnerability is a heap-based buffer overflow to trigger as CWE-122 and results in a remote code execution impact, meaning the attacker can run arbitrary code with the privileges of the affected service. The description does not indicate additional impact beyond code execution, so the primary risk is the compromise of the host or network.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations. All listed operating system and server editions that host Active Directory Domain Services are susceptible, and an authenticated attacker who can communicate with domain controllers over the network is required for exploitation.
Risk and Exploitability
Risk and exploitability: The CVSS score of 8.8 indicates high severity execution scenario. The EPSS score of less exploitation at present, and the vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is inferred to be network-based, requiring an authenticated attacker the vulnerable AD service. As a result, while the potential damage is significant, the overall probability of exploitation remains low under current threat conditions.
OpenCVE Enrichment