Impact
A relative path traversal flaw in the Windows User Interface Core component allows a locally authorized attacker to manipulate file paths that can result in an elevation of privileges on the host. This weakness corresponds to CWE‑23.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1 and Windows Server 2025, including Server Core installations, are affected.
Risk and Exploitability
The CVSS score of 7.8 categorizes the vulnerability as high severity, while the EPSS score of less than 1 % indicates that exploitation is uncommon. The flaw requires local authorized access, meaning an attacker must already have some user privileges to exploit it. It is not listed in the CISA KEV catalog, so no active exploitation campaigns are known.
OpenCVE Enrichment