Impact
A buffer over‑read in the Windows Overlay Filter allows an authorized attacker to elevate privileges locally on a Windows system. The flaw involves a buffer over‑read (CWE‑126) and integer overflow (CWE‑190) weaknesses, which can be exploited to gain higher permissions on the affected host.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; Microsoft Windows Server 2012 R2 (including Server Core), 2016, 2019, 2022 and 2025 (including Server Core) are affected.
Risk and Exploitability
The CVSS score of 7.8 reflects a high‑severity local privilege escalation. The EPSS score of less than 1% shows a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local, authenticated attacker who can trigger the buffer over‑read in the Overlay Filter service.
OpenCVE Enrichment