Impact
Stack-based buffer overflow in the Local Security Authority Server (lsasrv) allows a local attacker with sufficient privileges to overwrite return addresses on the stack and execute arbitrary code. The flaw enables privilege escalation, permitting the attacker to gain elevated local privileges or potentially full administrative control. The vulnerability is classified as CWE‑121 due to an uncontrolled buffer overflow.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and a range of Windows Server editions including 2012, 2012 R2, 2016, 2019, 2022, and 2025 – both standard and Server Core installations – are impacted. All affected releases are listed in the CNA product list and the supplied CPE identifiers.
Risk and Exploitability
The CVSS score of 7.8 indicates a moderate‑to‑high severity. Because the exploit requires local authenticated access, the attack vector is inferred to be local. The EPSS information is not available, and the vulnerability is not currently listed in the CISA KEV catalog. In environments where privileged accounts are widespread, an attacker could elevate privileges and expand the scope of a compromise. No public workaround is available, so applying the vendor patch is essential.
OpenCVE Enrichment