Impact
Access of a resource using an incompatible type, known as type confusion, occurs within the Windows Object Linking and Embedding (OLE) subsystem. This flaw allows an attacker who can supply malicious OLE data over a network to execute arbitrary code with the privileges of the local user or system service that processes the request. The impact includes full control over the affected machine as the attacker can run any code that the account can run. This vulnerability is classified as a critical Remote Code Execution flaw reflected by its CVSS score of 8.1.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022, 2025. The affected builds run on x86, x64 and arm64 architectures where applicable. All these operating systems contain the vulnerable OLE component that must be patched.
Risk and Exploitability
The CVSS score indicates a high severity defect, yet the EPSS score of less than 1 percent shows a very low likelihood of exploitation in the wild at present. Nonetheless, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, meaning no publicly available exploit has been observed, but the possibility remains. Attackers would likely need to craft a malicious OLE object and deliver it over the network to a target that processes OLE data, making the typical attack vector an authenticated or unauthenticated network or local interaction with the OLE service. Because remote code execution can lead to privilege escalation and complete system compromise, the risk to both client and server deployments remains high.
OpenCVE Enrichment