Impact
The vulnerability is a heap‑based buffer overflow in the Windows Media component that permits a locally authenticated attacker to increase privileges. This flaw corresponds to CWE‑122 and allows the attacker to execute code with higher privileges on the affected system. Based on the description, it is inferred that the attack vector requires an authorized local user with access to Windows Media.
Affected Systems
Affected products include Microsoft Windows 11 version 24H2 (arm64), Windows 11 version 25H2 (arm64), and Windows 11 version 26H1 (x Media component across these releases.
Risk and Exploitability
The CVSS score of 7.8 marks this flaw as high severity, but the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in CISA's KEV catalog, yet it remains a significant risk for local users who can leverage the elevated privileges to compromise system integrity. The likely attack vector is a locally authenticated user exploiting a heap overflow in Windows Media.
OpenCVE Enrichment