Impact
The vulnerability is an integer overflow or wraparound in the Windows Web Proxy Auto-Discovery Protocol (WPAD) parsing logic. The overflow can lead to a buffer overflow (CWE‑122) which, when triggered by an attacker, can result in an elevation of local privileges. Based on the description, it is inferred that the attacker must be able to supply crafted WPAD traffic or otherwise influence the protocol handler on a machine where the attacker already has some local access.
Affected Systems
This issue affects Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 releases 24H2, 25H2, 26H1; and Microsoft Windows Server releases 2019, 2022, and 2025, including Server Core installations. The vulnerability applies to x86, x64, and ARM64 architectures as reflected in the supporting CPE identifiers.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of <1 % signals a low probability of exploitation in the wild; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a locally authenticated, authorized user who can present malicious WPAD traffic, and is therefore generally limited to insider or compromised machines. Nonetheless, the potential to grant the attacker full system control justifies immediate action.
OpenCVE Enrichment