Impact
The vulnerability is a heap‑based buffer overflow in the Desktop Window Manager component that allows a local attacker with authorized access to elevate privileges. This is a classic buffer overflow (CWE‑122) combined with an out‑of‑bounds read (CWE‑125), giving the attacker administrative rights or the same privilege level as the current user, enabling the installation of malicious software, data theft, or lateral movement.
Affected Systems
Affected systems include Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025 (including Server Core installations). The Desktop Window Manager component is impacted across these versions, so administrators should verify whether these builds are present in their environment.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the lack of an EPSS score means the current exploitation probability is uncertain. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local; an attacker must already be logged into the system with authorized rights to trigger the overflow. While no publicly disclosed exploit is known, the high CVSS and local privilege escalation nature recommend prompt remediation.
OpenCVE Enrichment