Impact
Execution with unnecessary privileges in the Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. The flaw is a classic privilege‑elevation vulnerability (CWE‑250) that could enable a malicious user to gain higher rights than intended.
Affected Systems
Microsoft Windows App Client for Windows Desktop – the HPC Pack component. No specific product or version numbers are provided in the advisory, so any installation of the HPC Pack on Windows Desktop is potentially affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, classifying it as high severity. EPSS is not available, and it is not listed in CISA’s KEV catalog, but the high CVSS indicates a serious risk. The likely attack vector is remote or network‑based, requiring an attacker with already authorized access to the HPC service to expand their privileges. Because the flaw permits elevation over a network, attackers can affect multiple users or systems if the HPC Pack is exposed to untrusted hosts.
OpenCVE Enrichment