Impact
A stack-based buffer overflow (CWE-121) in the Windows File History Service allows an attacker who already has local user‑level access to write beyond a stack buffer, corrupt control data and elevate privileges to SYSTEM. This bypass enables full administrative control over the affected machine.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, 22H2; Windows 11 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, 2025 and their Server Core installations.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8 and an EPSS score of < 1%, indicating a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack vector requires that an authorized local user is able to execute code that targets the File History Service; once executed, the stack corruption can lead to privilege escalation to SYSTEM, providing full control over the machine.
OpenCVE Enrichment