Impact
An attacker who is already authenticated on the system can exploit an improper access control bug in Windows Win32K to elevate local privileges. The flaw enables the attacker to run code with higher rights than intended, potentially granting full control over the affected machine. No remote or cross‑system impact is claimed; the compromise remains local to the user who initiates the exploit.
Affected Systems
Affected products include all listed Windows 10 releases from Version 1607 to 22H2, Windows 11 releases 24H2, 25H2, and 26H1, and Windows Server editions from 2012 (full and Server Core) through 2025 (full and Server Core). The flaw is present in the core operating system components of each of these versions.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate to high impact when successfully exploited. The EPSS score is reported below 1%, showing that real‑world exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local; an authorized user must be present to trigger the privilege escalation. If a local attacker gains the required privileges, the flaw can be leveraged to compromise the entire system.
OpenCVE Enrichment