Impact
Missing authorization within the Windows Defender Firewall Service permits a local, authorized user to bypass firewall security settings. This flaw allows the attacker to alter or disable firewall rules, potentially enabling unauthorized inbound or outbound network traffic and compromising the confidentiality and integrity of data exchanged over the network. The weakness is formally classified as CWE-862, indicating an improper authorization control.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2019; Windows Server 2022; and Windows Server 2025—including Server Core installations—are all affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1% suggests that the likelihood of this vulnerability being exploited in the wild is presently very low. The vulnerability is not listed in CISA’s KEV catalog, reinforcing that widespread exploitation has not been observed. Exploitation requires a local user with authorization to modify firewall settings; an attacker can leverage the missing authorization check to change rules or disable the firewall, but the scope of impact remains confined to the local system unless the attacker also gains higher privileges or remote access.
OpenCVE Enrichment