Impact
A flaw in Windows Connected User Experiences and Telemetry allows an authorized, local attacker to exploit a type confusion error, resulting in elevation of privilege. The vulnerability is classified as CWE-843, indicating that the system performs an operation on a variable using an incorrect data type. An attacker with sufficient access can use this gap to perform actions normally restricted to higher privilege levels, potentially modifying system settings or accessing protected resources.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; and Microsoft Windows Server 2016, 2019, 2022 and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 categorizes this issue as a high severity local privilege escalation. Although the EPSS score is less than 1%, indicating a low probability of exploitation, the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local: an attacker who can authenticate to the target machine with user privileges can trigger the type confusion and subsequently gain elevated rights. The impact would allow malicious modification of system configuration or unauthorized access to sensitive data on the affected machines.
OpenCVE Enrichment