Impact
Improper access control in the Windows kernel, identified as a CWE‑284 vulnerability, allows an authorized local attacker to elevate privileges and gain administrative control on the system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2019, Server 2022 and Server 2025, including server core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of local privilege escalation. The EPSS score is less than 1%, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an authorized user or compromised account to trigger the flaw. While the CVE does not describe remote exploitation capabilities, the impact of gaining elevated privileges is significant, enabling full control over the compromised machine.
OpenCVE Enrichment