Impact
Windows Wireless Wide Area Network Service (WwanSvc) contains a deserialization flaw (CWE‑502) that allows an authorized local attacker to execute privileged code. By supplying crafted data to the service, the attacker can gain higher privileges on the affected host, potentially compromising system integrity and confidentiality.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, and 2025, including their Server Core installations. Affected builds include 32‑bit, 64‑bit, and ARM64 platforms as specified by the vendor release notes.
Risk and Exploitability
With a CVSS v3.1 score of 7.8, the flaw is classified as high severity. Its EPSS score of 3% indicates a low but not negligible probability of exploitation in the wild, and there is no current listing in the CISA KEV catalog. The attack vector is likely user‑level access to target machine to the is processed by the service, an unauthorized elevation of privileges can occur, enabling the attacker to install software, alter configurations, or access sensitive data.
OpenCVE Enrichment