Impact
the Windows kernel. The flaw allows a user with local, authorized privileges to execute code in a privileged context, thereby elevating their access level. The weakness is classified as CWE‑122, a heap‑based compromises integrity and authority of the affected system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2 and Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2019 full installation and Server Core, Windows Server 2022, and Windows Server 2025 full installation and Server Core are vulnerable.
Risk and Exploitability
The vulnerability received a CVSS score of 7.8, indicating high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. Attackers require local, authorized system access to craft the heap payload that triggers the overflow; failure to do so would not result in successful privilege escalation. Because the flaw resides in the kernel, successful exploitation would grant complete control over the affected machine.
OpenCVE Enrichment