Impact
An integer underflow condition exists within the Windows Program Compatibility Assistant Service. When triggered by a local user possessing sufficient rights to interact with the service, the flaw allows that user to bypass access restrictions and elevate privileges. The weakness corresponds to CWE‑191 and can lead to local privilege escalation, granting the attacker broader system capabilities such as modifying system settings or installing software.
Affected Systems
The vulnerability affects multiple Windows platforms including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server editions 2016, 2019, 2022, and 2025 (both full and Server Core installations).
Risk and Exploitability
The CVSS score of 7.8 categorizes this as a high‑severity flaw. The EPSS score of 3% indicates a modest likelihood of exploitation, but the absence of a KEV listing suggests that attacks are not yet widely observed. Based on the description, the likely attack vector is a local authenticated attacker who can invoke the problematic service, possibly by crafting specific requests that trigger the integer wraparound. Once the underflow occurs, read/write privileges on system resources are effectively escalated.
OpenCVE Enrichment