Impact
A heap-based buffer overflow (CWE-122) and an out‑of‑bounds read (CWE-125) in the Desktop Window Manager allow an authorized local attacker to gain elevated privileges on the target machine, potentially elevating to system level and bypassing security controls that rely on the current user level.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016 (including Server Core), 2019, 2022, 2025 (including Server Core) are affected.
Risk and Exploitability
The severity is assessed with a CVSS score of 7.8, indicating a high risk if the flaw is exploited. The EPSS score of 0.00246 (≈0.25%) indicates a very low but nonzero likelihood of exploitation; this suggests that the vulnerability is not widely exploited but could be targeted in the future. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. The attack vector is local and requires the attacker to have an existing authenticated session to trigger the overflow; once triggered, the attacker can elevate privileges to system level on the impacted Windows platforms.
OpenCVE Enrichment