Impact
Heap based buffer overflow within the Windows Win32K graphics component permits an attacker with an authorized network presence to gain higher privileges. The flaw originates from improper handling of memory allocation when processing user supplied input, enabling the attacker to execute arbitrary code with elevated privileges. This vulnerability is classified as a Buffer Overflow (CWE-122) and a Data Conversion Error (CWE-197), both of which compromise confidentiality, integrity, and availability of the targeted system.
Affected Systems
The vulnerability affects multiple Windows operating systems, including Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 through 26H1, and Windows Server editions from 2012 through 2025. All editions across 32‑bit, 64‑bit, ARM64, and server core configurations are impacted as detailed by the CNA vendor/product list.
Risk and Exploitability
The CVSS score of 8 indicates high severity, and although the EPSS score is not available, the lack of a KEV listing does not mitigate the risk. Authorized attackers within a network can exploit the heap overflow to execute code at elevated privilege level, compromising host integrity and potentially allowing full system takeover if additional lateral movement is enabled.
OpenCVE Enrichment