Impact
The vulnerability is an untrusted search path flaw in Windows Storage that lets an attacker with local access override trusted components to gain higher privileges. This flaw maps to CWE‑426 and permits an actor to execute code with elevated rights, potentially up to SYSTEM, thereby compromising confidentiality, integrity, and availability of the affected system. An attacker must already have authorized local access, but no higher privileges are required, so a standard user can abuse the search path to elevate.
Affected Systems
Microsoft Windows 10 releases from version 1607 through 22H2, Windows 11 releases 23H2, 24H2, 25H2, 26H1, Windows Server 2016, 2019, 2022, and 2025 (both full and core installations). The affected platforms include x86, x64, and arm64 as appropriate.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score is not available, so there is no current exploit probability data. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation yet. The attack vector is local, requiring an authorized user to place a malicious executable in the search path; no remote code execution is possible. The risk is elevated for environments where untrusted files may be placed in storage paths, such as shared directories, or where the search path is not tightly controlled.
OpenCVE Enrichment