Impact
The Windows Program Compatibility Assistant Service contains a heap-based buffer overflow that can be triggered by an authorized local user, allowing an attacker to elevate privileges on the affected system. This vulnerability is a local privilege escalation that could enable the execution of malicious code with higher privileges, potentially compromising the entire system. The weakness corresponds to CWE‑122.
Affected Systems
Affected systems are Microsoft Windows 10 builds 1607, 1809, 21H2 and 22H2, Windows 11 builds 23H2 through 26H1, and Windows Server 2012 through 2025, including their Core installations. The impacted component is the Program Compatibility Assistant Service running on these operating systems.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity local privilege escalation. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the absence of a KEV listing suggests no wide-scale active exploitation has been observed. The attack vector requires local authorization and the ability to trigger the buffer overflow, typically by executing malicious code that targets the service. Once exploited, elevated local privileges can enable installing software, altering system settings, or compromising other users.
OpenCVE Enrichment