Impact
The vulnerability is a heap-based buffer overflow in Windows Error Reporting that allows an attacker who already has local access to escape normal privilege boundaries and gain administrative rights. The flaw is categorized as a heap corruption issue (CWE‑122). If successfully exploited, the can execute code with elevated privileges on the compromised system, enabling further compromise of the local environment.
Affected Systems
Microsoft Windows 10 and Windows 11 clients, including versions 1809, 21H2, 22H2, 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2019, Server 2022, and Server 2025 (including Server Core installations). The listed operating systems are affected regardless of specific language or processor architecture.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score is unavailable, so the likelihood of exploitation in the wild is uncertain. The vulnerability is not currently in the CISA KEV catalog. The attack likely requires local presence or an authorized user context to trigger the error reporting mechanism, after which the memory corruption can be leveraged to run arbitrary code with escalated privileges.
OpenCVE Enrichment