Impact
Out-of-bounds read within Windows Win32K’s GRFX component allows an authorized local user to read memory beyond intended bounds and elevate privileges. This flaw, a classic out‑of‑bounds read (CWE‑125), can be abused for local privilege escalation, compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected versions include Microsoft Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1), and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score of less than 1% signifies a low likelihood of real-world exploitation. The vulnerability is not in the CISA KEV catalog, so currently no operational exploitation has been documented. Attackers require local access to an authenticated user, making environments with weak local account controls more susceptible. Prompt application of the available update removes the risk of privilege escalation.
OpenCVE Enrichment