Impact
The vulnerability is a heap‑based buffer overflow located in the Windows Shell component. An attacker who already has local access to the system can trigger the overflow, causing the operating system to write beyond the bounds of a heap buffer. This overflow allows the attacker to increase their privileges on the machine, enabling them to execute code or modify system objects with elevated rights. The flaw aligns with CWE‑122 and poses a threat to confidentiality, integrity, and availability if privilege escalation is achieved.
Affected Systems
Affected products are Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server‑Core installations.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, indicating that successful exploitation could lead to significant system compromise. The EPSS score of 0.00246 indicates a very low but non-zero probability of exploitation; based on the description, it is inferred that the vulnerability likely requires local access with administrative privileges and does not involve network exposure. Therefore the risk is primarily to users who already have local access. The vulnerability is not listed in CISA’s KEV catalog, so no publicly known exploits are documented yet. Nevertheless, a motivated adversary can craft an exploit to elevate privileges on vulnerable machines.
OpenCVE Enrichment