Impact
A heap‑based buffer overflow in the Windows Remote Access API allows an attacker with authorized local access to override normal privilege checks and gain higher privileges on the affected system. The flaw is a classic out‑of‑bounds write that can corrupt control data, enabling unauthorized elevation of privileges.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations) are affected. All listed releases are vulnerable; specific patch or update details are not included in the provided data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score of < 1 % suggests that exploitation in the wild is unlikely at present, and it is not recorded in the CISA KEV catalog. The expected attack vector is local, requiring an attacker to already have authorized access to the affected system or to execute code through the Remote Access API. If leveraged, the attacker can elevate their privileges to the level of the system or an administrator, potentially gaining full control over the machine.
OpenCVE Enrichment