Impact
The Windows Sensor Data Service mishandles the indexing of an array, causing a by an authorized local user to gain escalated privileges. As a result, an attacker who currently has a user account on the machine can raise their permissions to a privileged level and thereby compromise the confidentiality, integrity, and availability of the system. The weakness is a combination of improper validation of an array index (CWE‑118) and improper privilege identification (CWE‑822).
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core) are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, but the EPSS score of less than 1 % shows a very low probability of exploitation in the Near Term. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. According to the description, the attack requires an existing local user account; no network or remote vector is known. An attacker can trigger the fault by interacting with the Sensor Data Service, which subsequently grants them higher privileges.
OpenCVE Enrichment