Impact
The vulnerability involves a type confusion flaw in Windows Performance Monitor that allows an authorized local user to supply input that is incorrectly interpreted as a different data type, which may grant elevated privileges on the affected system. The CVE explicitly notes that this flaw can be exploited to elevate privileges locally, but no further impact details such as system compromise or malware installation are documented.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with authorized local access, meaning that any user able to run Performance Monitor may trigger the flaw; no public exploit is documented. Organizations should assess whether such local users have administrative privileges.
OpenCVE Enrichment