Impact
A heap-based buffer overflow exists in Active Directory Domain Services, enabling an authorized local attacker to elevate privileges on the system. This overflow can overwrite memory structures that control access rights, allowing the attacker to gain higher kernel or administrative permissions. The impact is a full compromise of the affected host, granting the attacker the ability to install software, modify system configurations, and potentially pivot to other network resources.
Affected Systems
Affected products include various Microsoft Windows operating systems, such as Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server releases 2016, 2019, 2022, and 2025, both in standard and Server Core installations. Each variant is listed in the CNA, indicating a broad impact across desktop and server environments.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity for local privilege escalation, while the EPSS score is unavailable, so the likelihood of widespread exploitation is unclear. The vulnerability is not currently listed in the CISA KEV catalog. Because the attack requires local authorization, the disruption is limited to environments where an attacker has at least basic access to the machine. However, once privileges are elevated, the attacker can fully compromise the host, so the risk remains significant. The likely attack vector is local execution by an authorized user, such as a system administrator or a malicious insider who gains user-level access.
OpenCVE Enrichment