Impact
This vulnerability arises from an integer underflow in a Windows kernel‑mode driver, allowing an attacker who can run code locally to gain higher privileges. The flaw permits bypassing normal privilege checks, potentially elevating an authorized user to SYSTEM level. The weakness is categorized as CWE‑122 (Buffer Overflow) and CWE‑191 (Integer Underflow or Wraparound).
Affected Systems
Microsoft Windows 10 for versions 1607, 1809, 21H2, and 22H2; Windows 11 for versions 23H2, 24H2, 25H2, and 26H1; as well as Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity vulnerability. Exploitation requires local authorized execution of the vulnerable driver, and the attack vector is therefore likely local rather than remote. The EPSS score is currently not available, and the flaw is not listed in the CISA KEV catalog, so the exploit probability could not be quantified at this time. Nonetheless, the high CVSS rating indicates that once the flaw is used an attacker could easily compromise system integrity.
OpenCVE Enrichment