Impact
The flaw is a command injection vulnerability in the Windows Clipboard User Service. An attacker who can run applications in the user context can inject specially crafted input that is passed to a system command without proper neutralization, allowing the attacker to execute commands with elevated privileges. This could enable the attacker to gain full SYSTEM rights, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 11 24H2 and 25H2, both including ARM64 builds, as well as Windows Server 2025 in full and Server Core editions are affected. The vulnerability is specific to the Clipboard User Service component in these operating system releases.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of <1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and an authorized user context, but the ability to elevate privileges to SYSTEM presents a high impact if the attacker is present on the machine.
OpenCVE Enrichment