Impact
Integer overflow or wraparound in Windows Terminal enables an unauthorized attacker to execute code over a network. The flaw is a classic integer overrun (CWE‑190) that can compromise confidentiality, integrity, and availability by allowing arbitrary code execution on the victim system.
Affected Systems
Microsoft Windows Terminal App is affected. Versions are not specified in the advisory, so all current releases may be vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% shows that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based approach targeting the Windows Terminal service, requiring an attacker to be able to send crafted data to the application. Given the low exploitation probability, the overall risk is moderate for environments that expose the Terminal to external networks.
OpenCVE Enrichment