Impact
Out-of-bounds read in the Local Security Authority Server allows an authorized attacker over a network to elevate privileges. The flaw permits reading memory beyond intended bounds, enabling the attacker to gain higher permissions on the affected machine without proper authentication.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1, and Microsoft Windows Server 2022 and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 8 indicates high severity. Although EPSS data is not available, the vulnerability requires an attacker with network access and valid credentials to interact with the LSA service, allowing privilege escalation. The flaw is not listed in the CISA KEV catalog, but its potential to raise an authorized user’s privileges presents a serious risk to organizations that expose the affected systems over a network.
OpenCVE Enrichment