Impact
The vulnerability is an improper authorization check in the Windows RPC Runtime that allows a logged‑in user to send privileged RPC calls and bypass normal access controls, thereby elevating their privileges to a system level. This flaw, identified as CWE‑285, can enable an attacker to modify system configuration, install software, or execute arbitrary code with full system rights, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects a wide range of Windows desktop and server releases. Vulnerable versions include Windows 10 1607, 1809, 21H2, and 22H2; Windows 11 24H2, 25H2, and 26H1; and Windows Server editions from 2012 through 2025, including both full installations and Server Core releases.
Risk and Exploitability
The CVSS score of 7.8 reflects high severity, while the EPSS score of less than 1% indicates a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is local: any user authenticated to the system can abuse the improper authorization in the RPC Runtime, typically by sending privileged RPC requests from the local machine. An attacker who succeeds can gain full system privileges, read or alter critical data, and potentially install persistence mechanisms.
OpenCVE Enrichment