Impact
A heap-based buffer overflow occurs in the Windows Display Enhancement Service, allowing an authorized local attacker to gain elevated privileges. The flaw permits the attacker to craft a payload that overflows a heap allocation and changes the program’s execution flow, ultimately enabling the attacker to run code with higher privileges, potentially reaching SYSTEM level. This results in the ability to modify system configuration, install malicious software, or exfiltrate data, impacting confidentiality, integrity, and availability of the affected machine. The weakness is classified as CWE-122, indicating a classic heap-based overflow scenario.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2019 and the Windows Server 2019 Server Core installation; Microsoft Windows Server 2022; Microsoft Windows Server 2025 and the Windows Server 2025 Server Core installation are all impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, whereas the EPSS score of less than 1% suggests a currently low probability of exploitation. This CVE is not listed in the CISA KEV catalog, so it has not yet been widely documented as a known exploited vulnerability. The vulnerability requires an attacker with local user privileges to run malicious code; from that position the exploit can be leveraged to elevate those privileges. While the low EPSS indicates limited active exploitation, the high CVSS and local nature of the attack still represent a significant risk to environments where privileged access is not tightly controlled.
OpenCVE Enrichment