Impact
The vulnerability is an out‑of‑bounds read (CWE‑125) in the Windows kernel that allows an authorized local attacker to elevate their rights to a higher privilege level. Because the flaw involves incorrect memory boundary checking, a successful exploitation can give the attacker elevated privileges, enabling them to perform actions that require those privileges.
Affected Systems
Microsoft Windows 10 Version 21H2 and 22H2, Microsoft Windows 11 Versions 24H2, 25H2 and 26H1, Microsoft Windows Server 2022 and Windows Server 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.8 marks this flaw as high severity, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an authorized user or a process with elevated privileges to trigger the out‑of‑bounds read and subsequently gain higher privileges.
OpenCVE Enrichment