Impact
The flaw is a missing authentication check in a critical function of the Windows Power Dependency Coordinator. An attacker who already has authorized local access can tamper with the component, potentially modifying its behavior or configuration. No additional impact beyond local tampering is described in the CVE data.
Affected Systems
Affected are Microsoft Windows OS versions 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1) across x86, x64, ARM64 builds, and Windows Server releases from 2012 through 2025, including Server Core installations. The vulnerability applies to both standard and core image types.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker already possess authorized local credentials; no additional network or remote access prerequisites are mentioned. Once local access is achieved, tampering can be performed without further conditions.
OpenCVE Enrichment