Impact
A heap-based buffer overflow in the Windows Win32K graphics component allows an attacker who already has a user session on the system to elevate their privileges. The vulnerability matches CWE‑122, meaning that malicious data can corrupt the heap and enable arbitrary code execution inside the highly privileged Win32K process. As a result, a local attacker could run code with elevated system rights, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Affected systems include multiple Microsoft Windows releases: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025, including their Server Core installations. All mentioned versions run on x86, x64 or arm64 platforms.
Risk and Exploitability
The CVSS score is 7.8, indicating a high-severity local privilege escalation. EPSS is not available, so current real-world exploitation probability is unclear, but the lack of a KEV listing suggests no widely known public exploit yet. The attack vector is local; an attacker must already have a logged‑on session or ability to execute code on the target. If the system is compromised, an attacker could gain full system control, making this a critical risk for any organization that cannot immediately apply a patch.
OpenCVE Enrichment