Impact
The flaw is a heap‑based buffer overflow in the Windows Error Reporting (WER) component that allows a local attacker with authorized access to overwrite critical memory structures. This overflow can corrupt internal data and result in the attacker running code with elevated privileges on the local system. According to the reported weakness the attack logic is grounded in CWE‑122, which concerns unchecked or inadequate bounds checking of heap data.
Affected Systems
Microsoft products affected by this vulnerability include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2016, 2019, 2022, and 2025 in both base and Server Core installations. These versions are listed as impacted in the CNA vendor/product data provided.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity for a local privilege escalation scenario. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. However, because the vulnerability requires local user interaction, an attacker who can log in or otherwise gain authorized access can use WER to trigger the heap overflow and elevate privileges, which poses a significant risk to system confidentiality and integrity if exploited.
OpenCVE Enrichment