Impact
A heap-based buffer overflow flaw in the Windows Sensor Data Service permits an attacker who is already authenticated on the system to gain elevated privileges. The vulnerability is identified as CWE-122 and can allow the attacker to execute code with higher authority, potentially compromising system integrity and confidentiality.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server editions 2022 and 2025, including Server Core installations. The issue affects the Sensor Data Service component present on all these operating system builds.
Risk and Exploitability
The CVSS score of 7.8 indicates a high-risk vulnerability. EPSS is not provided, so the exploitation likelihood cannot be quantified. The flaw is not listed in the CISA KEV catalog, suggesting limited public exploitation yet. The likely attack vector is local; the attacker must have authorized access to the target machine to trigger the overflow.
OpenCVE Enrichment