Impact
The vulnerability is an omission of a required cryptographic step within the Windows Cryptography API, Next Generation (CNG). This missing step allows an attacker with local privilege (inferred from the description) to tam by integrity checks. The flaw is classified as CWE‑325 and can enable manipulation of cryptographically signed or encrypted content, potentially undermining authenticity and integrity of system data. The impact is confined to the local environment and does not provide remote code execution or privilege escalation beyond the authenticated user.
Affected Systems
Affected systems include Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2022, Microsoft Windows Server 2025, and the Windows Server 2025 Server Core installation.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, while the EPSS score of less than 1% signals that exploitation is unlikely in the wider user base. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers must be locally authenticated and possess sufficient privileges; therefore, the threat primarily concerns systems where privileged users operate, making the exploitation path limited to those accounts.
OpenCVE Enrichment