Impact
The vulnerability is a null pointer dereference in the Windows Kernel that enables an authorized local attacker to gain elevated privileges. It is a classic local privilege escalation flaw and maps to CWE‑367 and CWE‑476.
Affected Systems
Affected are Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1), as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations for the server editions.
Risk and Exploitability
CVSS score of 7.8 indicates moderate to high severity, while the EPSS score of less than 1% shows a low likelihood of exploitation. It is not listed in the CISA KEV catalog. The flaw can be leveraged only by a local user with sufficient access to execute code, implying an authorized local attacker is required. The mitigation is through the vendor patch.
OpenCVE Enrichment