Impact
A stack-based buffer overflow condition exists in the Windows Broker Infrastructure Service. When the service processes malformed input, an attacker who has local access and sufficient permission to interact with the service can exploit the overflow to gain elevated privileges on the machine. This local privilege escalation could enable the attacker to execute arbitrary code with higher-level rights, thereby compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability impacts several Windows operating system releases, including Windows 10 v1607, v1809, v21H2, v22H2; Windows 11 v23H2, v24H2, v25H2, v26H1; and multiple Windows Server editions such as Server 2016 (both standard and Server Core), Server 2019, Server 2022, and Server 2025. Both 32‑bit and 64‑bit architectures, as well as ARM64 versions of Windows 11, are affected according to the listed CPE entries. Administrators should verify whether their deployments run any of these versions.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. The most likely attack vector involves a local attacker with authorized access to the target machine who can trigger the overflow by interacting with the Broker Infrastructure Service. Successful exploitation would let the attacker attain higher privileges, potentially leading to full system compromise. Because the flaw requires local access, remote exploitation is unlikely unless additional foothold is gained.
OpenCVE Enrichment