Impact
The vulnerability is a null pointer dereference (CWE‑476) in Windows Image Acquisition that allows an authorized user running locally to gain higher privileges. It is a local privilege escalation flaw. An attacker can use this flaw to execute code with elevated rights, potentially compromising the system's security.
Affected Systems
The flaw affects Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 and its Server Core installation. The vulnerability is present in the Windows Image Acquisition component across these operating system releases.
Risk and Exploitability
The CVSS score of 7.8 indicates considerable severity for this local exploitation. The EPSS score of less than 1% suggests a low probability of exploitation under normal circumstances, and the vulnerability is currently not listed in the CISA KEV catalog. The likely attack vector is a local authorized user who can run code with limited privileges and then invoke the vulnerable component, leading to privilege escalation.
OpenCVE Enrichment