Impact
The vulnerability is a heap-based buffer overflow in the Windows Overlay Filter. An attacker who already has local access can trigger the overflow and overwrite memory to execute code with elevated privileges. The impact is local privilege escalation, allowing the attacker to gain administrative rights from otherwise unprivileged user accounts. This weakness is classified as CWE‑122.
Affected Systems
Affected on Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Windows Server 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations). The bug resides in the system core component, so all listed editions are impacted.
Risk and Exploitability
The assigned CVSS score of 7.8 indicates a high risk, yet the EPSS score is below 1 % and the flaw is not listed in the CISA KEV catalog, suggesting low current exploitation probability. Because the attack requires local authorized access, the vector is local; once the attacker triggers the overflow, privilege escalation occurs with no need for network exposure.
OpenCVE Enrichment