Impact
This flaw arises from is classified as a CWE‑284 weakness. An attacker who already has local access can bypass a built‑in security feature. Based on the description, it is inferred that the bypass could allow modification of protected kernel data or escalation of privileges within the local system. The vulnerability does not enable remote exploitation and requires the user to be authenticated on the affected machine.
Affected Systems
The defect affects a wide range of Microsoft Windows products including Windows 10 versions 1607, 1809, 21H2 and 22H2, Windows 11 versions 24H2, 25H2 and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, including their Server Core installations. All editions listed by the CNA are vulnerable.
Risk and Exploitability
The CVSS base score of 5.5 indicates moderate severity, but the EPSS score of <1% shows a very low probability of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploit campaigns. Based on the description, the likely attack vector is local; an attacker must already have legitimate local access to leverage the bypass.
OpenCVE Enrichment