Impact
The vulnerability is a heap‑based buffer overflow in the Windows Kerberos subsystem that lets an attacker who already has authorized local access raise privileges to higher local accounts. The flaw arises from an unchecked memory write that corrupts control data, allowing the attacker to execute arbitrary code with elevated rights. This is classified under CWE‑122, which indicates a critical heap overflow weakness.
Affected Systems
Affected are all Windows 10 releases from version 1607 through 22H2, all Windows 11 releases from 23H2 through 26H1, and all Windows Server releases from 2012 to 2025—including core installations and all processor architectures represented in the listed CPE strings.
Risk and Exploitability
The CVSS score of 7.8 ranks this issue as High severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV, implying a moderate threat profile. Exploitation requires local presence and an authorized user account; the attack vector is local. Once exploited, the attacker can execute arbitrary code and access or modify any data accessible to the higher privilege level, potentially compromising the entire local system. The lack of a known workaround highlights the urgency of applying the vendor’s patch.
OpenCVE Enrichment