Impact
A heap-based buffer overflow in the Windows Overlay Filter allows an authorized attacker to elevate privileges locally, enabling arbitrary code execution by overwriting critical memory structures as specified by CWE-122.
Affected Systems
Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server releases 2012 R2, 2016, 2019, 2022, and 2025—including both full and Server Core installations. All affected builds are those listed in the Microsoft Vendor products field.
Risk and Exploitability
The CVSS score of 6.7 reflects moderate severity for an exploitation requiring local authorization. EPSS data is not available and KEV has not listed this CVE, indicating no confirmed widespread exploitation yet. The likely attack vector is local: an attacker that can run code with privileged user rights on the target machine can abuse the overlay filter’s unchecked copy to gain administrative control. No remote exploitation path is documented, so networks and perimeter defenses provide passive protection against this flaw.
OpenCVE Enrichment