Impact
This vulnerability is a type‑confusion flaw (CWE‑843) in the Windows Kernel that permits an attacker with local user privileges or code execution to access a resource using an incompatible type and elevate their privileges. By exploiting this bug the attacker can gain administrator rights or higher, enabling full control over the system, including execution of arbitrary code, installation of malware, and unauthorized access to protected data.
Affected Systems
The flaw affects a broad set of Microsoft Windows products, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Core installations. All listed releases that ship the vulnerable kernel component are impacted.
Risk and Exploitability
The CVSS score of 7.0 indicates medium‑to‑high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The attack vector is local; an attacker must already have user or code execution on the target to trigger the type‑confusion and raise privileges. No publicly documented exploits are known, but the potential for full system compromise makes addressing this flaw a priority.
OpenCVE Enrichment