Impact
An integer overflow or wraparound in the Windows Projected File System lets an authorized user craft input that corrupts internal calculations, enabling the execution of processes with elevated system privileges. The flaw is correctly classified as a classic integer overflow (CWE‑190) and results in a local privilege escalation for a user who can influence the projected file system API.
Affected Systems
The vulnerability affects Microsoft Windows operating systems, including Windows 10 version 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2 and 26H1, and the Windows Server 2022 and Windows Server 2025 releases, including Server Core installations. All affected builds are listed in the Microsoft Security Update Guide with the identifier CVE‑2026‑62751.
Risk and Exploitability
The CVSS score of 7.8 indicates a high potential impact for local attackers, while no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been seen yet. The likely attack vector is a legitimate local user who can supply crafted input to the projected file system API; when successful, the attacker can run code with system privileges and compromise the entire system.
OpenCVE Enrichment