Impact
A heap-based buffer overflow occurs within Microsoft’s Input Method Editor (IME) component, allowing a local, authorized attacker to elevate privileges. The flaw arises when IME processes user input and writes to a heap buffer without proper bounds checking, leading to the overwrite of critical memory structures. Exploitation of this vulnerability can grant the attacker higher privileges on the affected system, potentially enabling additional attacks.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2016, Server 2016 Server Core, 2019, Server 2019 Server Core, 2022, 2025, and Server 2025 Server Core.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high‑severity local privilege escalation vulnerability. The EPSS score of less than 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The description explicitly states that a heap‐based buffer overflow in the Microsoft Input Method Editor allows an authorized local attacker to elevate privileges. Additional details on exploit prerequisites or input vectors are not provided.
OpenCVE Enrichment