Impact
A heap-based buffer overflow in the Windows kernel enables an attacker who can physically access the device to elevate privileges. The vulnerability is classified as CWE-122, indicating an untrusted control path that allows an attacker to overwrite critical memory structures and gain higher privileges than intended.
Affected Systems
The flaw impacts Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016 and 2019, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. Since the flaw requires physical access to the target system and is not listed in CISA’s KEV catalog, the immediate risk is limited to environments where attackers can reach the hardware. No public exploit has been identified, but the potential to arbitrarily elevate privileges warrants caution.
OpenCVE Enrichment