Impact
The vulnerability is an improper access control flaw in Windows System that permits an unauthorized local attacker to bypass a security feature. By bypassing the intended protection, the attacker can potentially gain unauthorized permissions or alter system state, compromising system integrity and possibly confidentiality. The weakness is classified as CWE‑284.
Affected Systems
Affected products include Microsoft Windows 11 24H2, 25H2, and 26H1 across ARM64 and x64 architectures, as well as Microsoft Windows Server 2022 and Window Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity vulnerability with a low but non-zero exploitation probability (EPSS < 1%). The issue is not listed in the CISA KEV catalog. The likely attack vector is local, meaning an attacker must be present on the affected machine to leverage this flaw. While the vulnerability does not grant full privilege escalation by itself, it enables bypassing an important security measure that could lead to further compromise if combined with other local privilege escalation techniques.
OpenCVE Enrichment