Impact
A heap-based buffer overflow in Windows Error Reporting can allow an authorized attacker with network-level access to elevate privileges on the impacted system. The flaw arises during processing of diagnostic data and can be exploited to gain higher access rights, thereby compromising confidentiality, integrity, and availability of the affected machine. This weakness is identified as CWE-122, a classic heap overflow vulnerability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, both full and core installations. The vulnerability was present across multiple architecture builds including x86, x64, arm64.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability. EPSS score is unavailable, which limits precise risk quantification, but the lack of exploitation data in KEV suggests no known widespread exploitation yet. The likely attack vector is over a network by an authorized user, and successful exploitation would permit privilege escalation. Given the high severity and the potential for critical systems exposure, immediate action is advised.
OpenCVE Enrichment