Impact
A heap-based buffer overflow in the Windows Overlay Filter can be triggered by an authorized local user. The vulnerability allows the attacker to execute arbitrary code with elevated local privileges, effectively bypassing the security model that separates user and system processes. As a result, a compromised application might run with administrative rights, read or modify restricted files, install malware, or extract credentials.
Affected Systems
The flaw affects Microsoft Windows 10 starting from version 1607 up to 22H2, Windows 11 from version 23H2 through 26H1, and Windows Server editions from 2012 R2 through 2025. All standard and server core installations are affected.
Risk and Exploitability
With a CVSS score of 7.8 the vulnerability is classified as high severity. The failure to allocate proper bounds checks in the overlay filter allows local users with authorization to elevate privileges. Current EPSS score is not available, and the issue is not listed in CISA's KEV catalog, suggesting no known widespread exploitation. Nonetheless, the local privilege escalation potential warrants prompt remediation to prevent privilege abuse or malware persistence.
OpenCVE Enrichment