Impact
This vulnerability is a heap-based buffer overflow in the DirectX graphics kernel of certain Windows operating systems. The flaw allows a local, authorized user to trigger an overflow condition that can elevate their privileges, potentially granting them full system access. The weakness is classified as CWE‑122, indicating that the code fails to validate buffer boundaries before memory writes.
Affected Systems
Affected Windows releases include Windows 10 versions 1809, 21H2, and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, and Windows Server releases 2019, 2022, and 2025 (including server‑core installations). These versions are listed in the vendor‑specific CNA data and correspond to the specified CPE strings.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.3, which indicates a moderate severity for local privilege escalation. The EPSS score of 2 % suggests a low-to-moderate likelihood of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Because the flaw requires an authorized local attacker to exploit it, the attack vector is inferred to be local and would typically involve a user with sufficient permissions to run code that interacts with the DirectX driver. No remediation exists beyond applying the Microsoft update, and the impact is confined to the system hosting the vulnerable DirectX components.
OpenCVE Enrichment