Impact
A heap‑based buffer overflow in the Windows Win32K graphics subsystem allows an attacker who already has local access to an account to write beyond the bounds of allocated memory. By exploiting this flaw, the attacker can elevate privileges on the affected machine, potentially gaining SYSTEM level rights and the ability to run arbitrary code or modify protected system files. The weakness is classified as CWE‑122, indicating an uncontrolled buffer overrun that compromises integrity and availability of the operating system for the local user.
Affected Systems
Microsoft Windows 11 24H2, 25H2, and 26H1, as well as Windows Server 2025 including Server Core installations, are all affected. The vulnerability applies to both arm64 (for the 24H2 and 25H2 builds) and x64 (for the 26H1 build). Users running earlier or later releases are not listed as impacted in the official CNA data.
Risk and Exploitability
The CVSS score of 7.8 places this issue in the high severity range, suggesting significant potential damage if exploited. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog, implying no widely known exploitation at the moment. However, because the flaw requires local authority to deliver crafted input to the Win32K subsystem, an attacker must be able to execute code or run a program locally with legitimate user credentials. In such an environment, exploitation could proceed with minimal detection if the malicious payload is crafted to avoid standard security defenses.
OpenCVE Enrichment