Impact
A heap‑based buffer overflow in the Windows Kernel allows an attacker who already has authenticated access to the system to elevate their privileges locally. This vulnerability is a CWE‑122 heap-based buffer overflow flaw.
Affected Systems
The vulnerability affects Microsoft Windows 10 (versions 1607, 1809, 21H2, and 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, and 26H1), and Microsoft Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score is 7, indicating moderate to high severity. The EPSS score is < 1%, so the current likelihood of exploitation is very low but non‑zero. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires the attacker to be an authorized user on the target machine. Exploitation would leverage the kernel heap overflow to achieve local privilege escalation.
OpenCVE Enrichment