Impact
A numeric truncation error in Microsoft Digest Authentication allows an attacker who already has local access to a Windows system to elevate their privileges. The flaw, identified as CWE‑197, can be exploited to execute code with higher privileges than the attacker originally possesses, potentially compromising the machine and any data it can access.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022 and 2025, including both full and Server Core installations.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity. An EPSS score of less than 1 % means current exploitation probability is very low, and it is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local: the attacker must already have logged onto the target system or otherwise have local access before they can abuse the authentication truncation to gain elevated privileges.
OpenCVE Enrichment