Impact
Improper access control in Windows Server allows an authorized attacker to elevate privileges locally, granting the attacker higher system privileges than their original account.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; Microsoft Windows Server 2012 through 2025, including all full and Server Core installations.
Risk and Exploitability
The CVSS base score of 7.8 indicates a moderately high severity, and an EPSS score of less than 1% suggests that widespread exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an authorized attacker to already be present on the machine or to exploit a trusted process with a pre-existing account.
OpenCVE Enrichment