Impact
A heap‑based buffer overflow in Windows URL Moniker enables an attacker to run arbitrary code on the target machine without authentication. The flaw allows code execution over a network connection, giving an attacker local‑privilege level executing as the user who renders the malicious URL.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2012 (full and core), 2012 R2 (full and core), 2016, 2019 (full and core), 2022, and 2025 (full and core). All affected platforms run on x86, x64, or arm64 architectures as indicated by the CPE list.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. EPSS is currently unavailable, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw from any network, provided they can deliver a malicious URL to a target system. No special elevation or administrative rights are required for the initial exploitation.
OpenCVE Enrichment