Impact
Untrusted pointer dereference in the Windows DirectX graphics kernel allows an authorized local attacker to execute arbitrary code in kernel mode. The flaw is rooted in inadequate validation of pointer input, which is classified as CWE‑822. Exploiting this vulnerability would give the attacker full control over the target machine, enabling any code to run with the highest privileges.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019 (both standard and Server Core), Windows Server 2022, and Windows Server 2025 (both standard and Server Core) are all affected.
Risk and Exploitability
The severity is high (CVSS 8.8) and the documented exploit probability is low (EPSS < 1 %). Because the flaw requires local authorization, the immediate risk is mainly to users with elevated privileges or users able to import malicious DirectX content implying the public exploitation pipeline is currently limited. Nonetheless, the impact of a successful exploit is total compromise of the affected system.
OpenCVE Enrichment