Impact
The vulnerability is a heap‑based buffer overflow in the Windows Data.dll component. This flaw arises from improper bounds checking when allocating heap memory, as described by CWE‑122 and CWE‑190. An attacker may trigger the overflow to run arbitrary code from a local context, granting local code execution on the affected system.
Affected Systems
The vulnerability impacts a wide range of Microsoft Windows operating systems, including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1) and Windows Server editions from 2012 up to 2025, regardless of the installation type (full or Server Core).
Risk and Exploitability
With a CVSS score of 7.8 the potential damage is high, but the EPSS score of less than 1 % indicates that exploitation in the wild is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local; an adversary would need to have some level of access to the target system to trigger the overflow and gain code execution capability.
OpenCVE Enrichment