Impact
The vulnerability is a heap‑based buffer overflow in the Microsoft Account component that lets an authorized local user gain higher privileges on the affected system. This flaw aligns with CWE‑122, which can lead to local privilege escalation when the overflow is triggered. The exploit could allow the attacker to execute code with elevated rights, potentially compromising system integrity and confidentiality.
Affected Systems
Microsoft Windows 11 Version 24H2 and 25H2, as well as Windows Server 2025 (including Server Core installations), are affected. The flaw is present in the Microsoft Account service on these platforms, and the patch applies to the stated versions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high risk level for local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have an authorized Microsoft Account session. Once the overflow is triggered, the attacker can gain elevated privileges on the machine. The lack of a publicly available exploit reduces immediate risk, but the severity suggests that administrative mitigation should be prioritized.
OpenCVE Enrichment