Impact
Improper access control in Microsoft's Extensible Storage Engine (ESENT) permits an attacker who already has local authorization to elevate privileges. The weakness is identified as CWE‑284, indicating a failure to enforce appropriate access checks, which could allow the user to gain higher privilege levels on the affected system.
Affected Systems
Microsoft Windows 10 Version 1809, Microsoft Windows Server 2019 and its Server Core installation, Microsoft Windows Server 2022, Microsoft Windows Server 2025, and Microsoft Windows Server 2025 Server Core are affected according to the CNA classification. These versions are covered by the security update referenced in the provided link.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as High severity, while the EPSS score of less than 1% indicates a low yet non‑zero probability of exploitation. The vulnerability can be leveraged only by an attacker who already possesses local access to the affected machine; it does not require remote network access, which is inferred from the description stating local privilege escalation. No publicly known exploits are listed in CISA’s KEV catalog, suggesting that exploitation is currently not documented in that dataset.
OpenCVE Enrichment