Impact
A heap-based buffer overflow exists in the Windows Overlay Filter, enabling an attacker who already has authorized access to elevate privileges on the target system. The flaw is a classic memory corruption vulnerability (CWE‑122) that can be triggered during the processing of overlay data. When successful, the attacker can gain higher privileges, potentially reaching system or administrator level, compromising the confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The vulnerability has a CVSS score of 8, reflecting a high severity rating. The EPSS score is 0.00703 (<1%), indicating a very low but nonzero exploitation probability, and the flaw is not listed in CISA’s KEV catalog, suggesting no current public exploitation but a significant potential for abuse. The attack likely requires prior authorized access or a compromise that can interact with the overlay filter on the network, after which the attacker may leverage the overflow to gain elevated privileges. Given the high CVSS score and the broad range of affected Windows releases, the risk remains substantial.
OpenCVE Enrichment