Impact
Improper access control in the Win32K component of Windows creates a local privilege escalation. An attacker who already has a local account can raise their privileges to a higher level. The flaw is classified as CWE‑284. Beyond increased privilege, no other effects are described in the official report.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server (2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations) are all affected across x86, x64, and ARM64 architectures as indicated by the CPE list.
Risk and Exploitability
The CVSS score of 7.0 marks this as a high severity local privilege escalation. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authorized local user or privileged process; no remote or network attack vector is advertised.
OpenCVE Enrichment