Impact
A stack‑based buffer overflow exists in the Windows Win32K graphics subsystem, allowing an authorized attacker who can run code locally to elevate privileges. The flaw resides in improper bounds checking of a stack buffer, making it a classic stack overflow (CWE‑121). If successfully exploited, the attacker can gain higher rights on the affected system without requiring network access or exploiting a service.
Affected Systems
The vulnerability affects Microsoft Windows operating systems including Windows 10 (Versions 1607, 1809, 21H2, 22H2), Windows 11 (Versions 23H2, 24H2, 25H2, 26H1), and Windows Server from 2012 through 2025 in both full and core installations. All listed builds are vulnerable to the described local privilege escalation.
Risk and Exploitability
The CVSS score of 7.8 indicates medium to high severity for local privilege escalation. No EPSS data is available, so it is unclear how often this flaw is currently being exploited. Because the attack vector is local and requires an attacker with some level of authorized or local access, the attack surface is limited to environments where users have insufficient privileges but can run arbitrary code. The vulnerability is not listed in CISA’s KEV catalog, suggesting it may not yet have known widespread exploitation. Nonetheless, given its potential to grant local users elevated rights, the risk to organizations with mismanaged privilege policies remains significant.
OpenCVE Enrichment