Impact
A heap-based buffer overflow in the Windows Win32K graphics subsystem allows an authorized local user to gain elevated privileges on the system. The vulnerability is documented as CWE-122, indicating that improper handling of heap data can lead to memory corruption that an attacker can exploit to execute arbitrary code with higher permissions.
Affected Systems
Affected products include all listed Windows 10 releases (1607, 1809, 21H2, 22H2), Windows 11 releases (24H2, 25H2, 26H1), and Windows Server editions from 2012 through 2025, including both full and Core installations.
Risk and Exploitability
The CVSS score of 8.8 reflects a high impact severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not currently identified in the CISA KEV catalog. The likely attack vector is a local context, with the attacker needing authorised access to the compromised machine, which is consistent with the nature of a privilege escalation flaw.
OpenCVE Enrichment