Impact
The vulnerability originates from missing authentication in Windows License Manager, enabling a local attacker to execute critical functions without proper privileges. This weakness allows the escalation of user rights on the system, potentially granting administrative level access. The associated weakness is identified as CWE‑306, indicating missing or insecure authentication.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2016, 2019, 2022, and 2025, both for full installations and Server Core. These versions run on x86, x64, arm64, and arm64 architecture variants as noted in the CPE list.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high severity. However, the EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local attacker who can run processes on the target system; they may elevate privileges by invoking the unauthenticated functionality of the Windows License Manager.
OpenCVE Enrichment