Impact
The vulnerability is a buffer over-read in the Windows Subsystem for Linux (WSL2) kernel that an attacker with local, authorized access can exploit to gain elevated privileges. This flaw allows the attacker to read memory beyond intended bounds, potentially leading to unauthorized modification of process memory or privilege escalation. The primary weakness corresponds to CWE-126, a classic out-of-bounds read condition.
Affected Systems
Microsoft Windows Subsystem for Linux (WSL2) is affected. No specific vulnerable version numbers are provided in the advisory, so all installations that use the on any Windows build should be considered at risk until an official fix is released.
Risk and Exploitability
The CVSS score of 7.8 classifies the bug as high severity, while the EPSS score of less than 1 % indicates that large-scale exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local, authorized user executing code in WSL2. Once a user has local access, they can trigger the buffer over-read to elevate privileges within the Windows host environment.
OpenCVE Enrichment