Impact
The vulnerability is an out-of-bounds read in the Code Integrity DLL (ci.dll) that can be triggered by an attacker with local authorized access. By reading memory beyond the intended buffer bounds, the attacker can on the affected Windows system, potentially gaining administrative rights and compromising the security posture of the machine.
Affected Systems
The flaw affects multiple Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, both full installations and Server Core editions.
Risk and Exploitability
The CVSS score of 7.0 classifies the vulnerability as high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known large-scale exploit in the wild. The likely attack vector is local, requiring the attacker to have some level of local access, after which privilege escalation can be achieved. Overall, organizations should prioritize applying the vendor's fix to reduce potential risk.
OpenCVE Enrichment