Impact
The vulnerability is a heap‑based buffer overflow in the Windows Kerberos authentication subsystem that can be triggered by an authorized local attacker; exploiting it elevates the attacker’s privileges, allowing execution of privileged code on the affected machine. This flaw, identified as CWE‑122, occurs when the Kerberos service processes an oversized data structure and writes past its bounds, corrupting heap memory used to control the service. No public exploit has been reported, but an authorized user could manipulate a Kerberos request to trigger the overflow and gain higher privileges on the local system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity; the EPSS score is below 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the flaw requires an authorized local user and a crafted Kerberos request, making exploitation complex, but it allows local privilege escalation that can compromise the confidentiality, integrity, and availability of the compromised system.
OpenCVE Enrichment