Impact
The vulnerability lies in the Windows Filtering Platform’s insufficient granularity of access control. An attacker who already has privileges can perform actions reserved for higher‑privileged accounts. The weakness is identified by CWE‑1220, indicating inadequate permission checks within a trusted component. The impact is limited to the local system on which the attacker can execute code.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate‑to‑high severity local privilege escalation. The EPSS score of less than 1% suggests that, as of this assessment, the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires the attacker to already have an authenticated session on the affected machine. The risk is limited to environments where users have administrative or similar privileges and patching has not yet been applied.
OpenCVE Enrichment