Impact
The vulnerability is a heap-based buffer overflow in the Windows DWM Core Library, classified as CWE-122. An attacker with local user privileges can exploit the overflow to run arbitrary code with higher privileges, thereby escalating privileges on the affected system. Because the overflow occurs in a core system component that operates with system rights, the impact is comparable to a full enumeration of the machine, enabling the attacker to compromise data integrity and confidentiality.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server editions 2016, 2019, 2022, and 2025. All listed editions are susceptible when running the default configurations that include the DWM Core Library.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. With no EPSS score available, specific exploitation frequency cannot be quantified, but the known local privilege escalation potential suggests organizations should treat it as a high risk. Because it is not flagged in the CISA KEV catalog, there are no publicly confirmed active exploits yet, although the potential exists. The vulnerability requires that the attacker already have local access to the target system, so physical or remote authorized user access is necessary to trigger the buffer overflow.
OpenCVE Enrichment