Impact
An integer overflow or wraparound condition exists in the Windows Active Directory component that permits an attacker who already has some level of local access to raise their privileges on an affected system. The vulnerability is categorized as an integer overflow (CWE‑190) and a buffer overflow (CWE‑122). No explicit claims are made about compromising confidentiality, integrity, or availability beyond the elevation of privileges, so the primary impact is a local privilege escalation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025 (including Server Core installations). These are exactly the products and versions listed in the provided vendor/product table and the CPE strings.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1 % suggests a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploits. Based on the description, it is inferred that the attack vector is local: an attacker must already have some local access to trigger the integer overflow in Active Directory. Consequently, the risk is limited to compromise or privilege escalation by authorized or partially privileged local users.
OpenCVE Enrichment