Impact
The vulnerability arises from a cryptographic primitive that is implemented in a risky manner within Windows Key Guard. This flaw enables an authorized local user to bypass the security feature that Key Guard is designed to enforce. The weakness belongs to CWE-1240, which identifies improper cryptographic implementation.
Affected Systems
Administrators should note that the affected products are Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Windows Server 2019 (both standard and Server Core), Windows Server 2022, and Windows Server 2025 (both standard and Server Core).
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity for a vendor‑local exploit that requires privileges already held by a legitimate user. The EPSS score of less than 1 % shows that current exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is local and requires an authorized user; the flaw does not facilitate remote code execution or denial of service, but it does undermine the protection that Key Guard is meant to provide.
OpenCVE Enrichment