Impact
A heap-based buffer overflow exists in the Desktop Window Manager component of Microsoft Windows, permitting an attacker who has local system access to execute code with elevated privileges. This flaw can corrupt heap memory and lead to privilege escalation, thereby compromising the confidentiality, integrity, and availability of the entire system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, but the EPSS score of less than 1% and the absence of this vulnerability in the CISA KEV catalog suggest exploitation is unlikely at present. The attack vector is local: an authenticated or single-privilege user who can trigger the overflow may gain full control of the machine, enabling any malicious activity that requires administrator rights.
OpenCVE Enrichment