Impact
The vulnerability is a null pointer dereference in the Windows Graphics Kernel that permits an attacker to cause a denial of service. Because the kernel crash terminates graphics subsystems, a single corrupted request can bring the system to an unusable state for all users. The weakness is categorized as CWE‑476 and requires an unauthorized attacker to send malformed content over the network, making the threat remote.
Affected Systems
Affected are Microsoft Windows products including Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server editions 2022 and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The EPSS score of less than 1% reflects a very low likelihood of exploitation in the field, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an unauthorized attacker to send malformed content over the network that is processed by the graphics kernel, leading to a service interruption. No remote code execution is provided by the flaw.
OpenCVE Enrichment