Impact
A heap-based buffer overflow exists inside the Microsoft JScript engine, allowing an unauthenticated attacker to execute arbitrary code on a vulnerable system. The flaw is exploited through a malicious script that is delivered over the network, and once triggered it can compromise the confidentiality, integrity, and availability of the affected machine. The identified weakness is CWE‑122, a classic heap buffer overflow vulnerability that can lead to remote code execution.
Affected Systems
The vulnerability impacts a wide range of Windows operating systems, including Windows 10 versions 1607, 1809, 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server releases 2012 R2, 2016, 2019, 2022 and 2025. The affected builds span x86, x64 and arm64 architectures as reflected in the supplied CPE data.
Risk and Exploitability
The CVSS score of 8.1 marks it as high severity; however, no EPSS data are available and it is not listed in the CISA KEV catalog, suggesting a moderate likelihood of widespread exploitation at present. The attack vector is network-based, requiring no authentication or elevated privileges on the target. An attacker would deliver a crafted JScript payload—such as through a compromised web page, mail attachment or network file—and the vulnerable JScript engine would then execute it with the privileges of the current user, potentially escalating to system-level control if the user is an administrator.
OpenCVE Enrichment