Impact
The vulnerability arises from a heap‑based buffer overflow in Active Directory Certificate Services, classified as CWE‑122. An attacker who already has local authorization can craft a payload that overflows a heap buffer, allowing the attacker to elevate privileges on the same host and thereby gain unauthorized control of system resources.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is considered high severity. The EPSS score is not provided, but the lack of presence in the CISA KEV list suggests no widespread exploitation documented yet. Attacks would require local access and the ability to interact with the AD CS service, making the vector likely local exploitation by compromised or administrative users.
OpenCVE Enrichment