Impact
The Windows Runtime that allows an authorized local user to elevate privileges. Exploiting this flaw gives an attacker local administrator rights, operations and potentially install malicious software. The weakness corresponds to CWE‑416, a classic memory corruption error.
Affected Systems
Microsoft Windows 10 Version 21H2, Microsoft Windows 10 Version 22H2, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 25H2, Microsoft Windows 11 Version 26H1, and Microsoft Windows Server 2025 (including Server Core installation).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need local or privileged access to the target, and the misuse requires the ability to execute code within the compromised memory region, indicating that local privilege escalation is the primary risk.
OpenCVE Enrichment