Impact
A heap‑based buffer overflow exists in the Windows kernel. An attacker who already has local access can trigger an overflow that allows them to gain elevated privileges. The flaw is a classic bounds‑check failure (CWE‑122) that can lead to arbitrary elevation of privilege on the affected systems.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2016, 2019, 2022, and 2025, including Server Core installations. All users of these editions are potentially impacted.
Risk and Exploitability
The severity is moderate to high with a CVSS score of 7.8, and the EPSS score is 2%, and the flaw is not listed in CISA's KEV catalog. Because the exploit requires local access, the attack vector is likely limited to authenticated users on the affected machines. Though the probability of exploitation is unknown, the potential for privilege escalation warrants prompt remediation.
OpenCVE Enrichment