Impact
Insufficient granularity of access control in the User-Mode Power Service (UMPS) permits an attacker who already has authenticated access to a Windows system to acquire higher privileges. The flaw allows the manipulation of service permissions, bypassing normal privilege boundaries and enabling elevation to local administrative level, thereby potentially allowing the installation of malware or alteration of critical system settings. This weakness is classified as CWE-1220, indicating an access control flaw.
Affected Systems
The vulnerability applies to Microsoft Windows 10 versions ranging from 1607 through 22H2, Windows 11 releases from 23H2 through 26H1, and Windows Server editions from 2012 through 2025, including both full and server‑core install bases. The affected builds cover x86, x64, and ARM64 architectures as outlined in the known CPE identifiers.
Risk and Exploitability
With a CVSS score of 7.8, the flaw is considered high severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Attackers need local presence and authorized access to exploit the flaw, making it a local privilege escalation rather than a remote attack. Successful exploitation would grant the attacker elevated local rights across the affected systems.
OpenCVE Enrichment