Impact
A heap‑based buffer overflow exists in the Windows Program Compatibility Assistant Service. The flaw can be triggered by an attacker with authorized network access and allows the attacker to execute code with elevated privileges. The vulnerability stems from improper heap handling (CWE‑122) and can lead to unauthorized privilege escalation. The primary consequence is that the attacker may gain system‑level access beyond the permissions originally held.
Affected Systems
Microsoft Windows releases from 10 version 1607 through 22H2, Windows 11 versions 23H2, 24H2, 25H2 and 26H1, and all Windows Server editions from 2012 through 2025 are affected. Both 32‑bit and 64‑bit builds are listed by the CPE data and are susceptible.
Risk and Exploitability
The CVSS score of 8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that no widespread public exploitation is known. The likely attack vector involves a legitimate network user sending crafted data that overflows the service’s heap. Successful exploitation results in privilege escalation, potentially allowing full control of the target system. Because the vulnerability requires authenticated access, mitigations should be applied promptly to reduce the risk.
OpenCVE Enrichment