Impact
The vulnerability is a heap‑based buffer overflow in the Windows Win32K subsystem. An attacker who has local authorization can supply crafted input to overflow a heap buffer, causing code execution with the privileges of the elevated process. This flaw permits an authorized user to increase their privilege level on the affected system, potentially compromising confidentiality, integrity, and availability of the machine. The weakness is classified as CWE‑122.
Affected Systems
The flaw affects Microsoft Windows 10 builds from 1607 to 22H2, Windows 11 releases from 23H2 through 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including core installations). All affected platforms run the Win32K graphics kernel, which is responsible for rendering.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for a local privilege escalation scenario, meaning an attacker can rapidly gain elevated rights. Although the EPSS score is not available and the flaw is not listed in CISA’s KEV catalog, the lack of publicly known exploits does not diminish the risk; any authenticated user could abuse the bug to elevate privileges. The attack vector is local, requiring the attacker to have some form of authorized user or process on the target machine. In the absence of mitigations, a single exploit could result in full system compromise.
OpenCVE Enrichment