Impact
The vulnerability is an integer overflow or wraparound in the Windows Web Proxy Auto-Discovery Protocol (WPAD) parsing logic. An authorized local attacker who can influence WPAD traffic can cause the protocol handler to miscalculate buffer sizes, leading to a memory corruption that elevates the attacker’s system privileges, potentially granting full control over the affected machine. The weakness is a classic integer overflow (CWE‑190) coupled with a buffer overflow (CWE‑122).
Affected Systems
Microsoft Windows 10 releases 1809, 21H2, 22H2; Microsoft Windows 11 releases 24H2, 25H2, 26H1; Microsoft Windows Server releases 2019, 2022, 2025, including Server Core installations. Affected architectures include x86, x64, and ARM64 variants as reflected in the listed CPE identifiers.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate severity, while the EPSS score of approximately 2% indicates a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a local authorized user and a successful trigger of the integer overflow in the WPAD protocol handler, which may be difficult to execute reliably. Nonetheless, the potential for elevation of privileges warrants proactive mitigation.
OpenCVE Enrichment