Impact
The vulnerability in the Windows Overlay Filter is an integer overflow or wraparound condition that permits an attacker with local authorized access to gain elevated privileges, potentially compromising system integrity and confidentiality.
Affected Systems
The flaw affects multiple Microsoft Windows platforms, including Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 releases 23H2, 24H2, 25H2, 26H1, as well as Windows Server editions 2012 R2, 2016, 2019, 2022, and 2025.
Risk and Exploitability
The CVSS score of 6.7 indicates moderate severity. The EPSS score is not available (value omitted), so exploitation probability cannot be determined from the current data. The vulnerability is not listed in the CISA KEV catalog. Attack prerequisites include local authorized access, implying the attack vector is local and requires the attacker to be authenticated. Until the patch is applied, users with local administrative rights may be able to exploit this vulnerability to elevate privileges.
OpenCVE Enrichment