Impact
A stack-based buffer overflow occurs within the Windows Win32K subsystem. An attacker who has been authenticated in the network environment can exploit this vulnerability and gain higher privileges. The overflow corrupts the stack, allowing the attacker to execute arbitrary code with elevated rights, thereby compromising confidentiality, integrity, and availability of the system. This can be leveraged by an authorized attacker within the network.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022, 2025. These include both full and core installations.
Risk and Exploitability
The CVSS score of 8 indicates high risk. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited widespread exploitation but still a significant threat given its impact. The likely attack vector is a local network, whereby an authorized user exploits the Win32K component to elevate privileges; no additional conditions are detailed in the description.
OpenCVE Enrichment