Impact
The vulnerability is a heap‑based buffer overflow in the Windows Web Proxy Auto‑Discovery Protocol (WPAD) that can be triggered by a local, authorized attacker interacting with WPAD services. The flaw allows memory corruption and the elevation of local user privileges to administrative levels, as the out‑of‑bounds write is a classic CWE‑122 condition. This gives the attacker the ability to change or delete data, install malware, or hijack the system, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 Version 1607, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016, including both standard and Server Core installations, are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact, while the EPSS score of less than 1% suggests a low incident probability at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, authorized access and likely involves manipulating WPAD discovery traffic over the local network, limiting the risk to environments where WPAD is enabled and locally authenticated users are present.
OpenCVE Enrichment