Impact
The vulnerability is an incorrect conversion between numeric types in Microsoft JScript that permits an unauthorized attacker to execute arbitrary code over a network. The flaw originates from improper type handling, which is identified as CWE‑681. If exploited, an attacker can run code with the privileges of the user or system that processes the malicious script, potentially gaining full control of the affected device, compromising confidentiality, integrity, and availability of data and services.
Affected Systems
Affected systems include several versions of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and multiple Windows Server editions from 2012 through 2025, both standard and server core installations. The corresponding Microsoft Windows operating systems are listed with specific build identifiers in the vendor products list.
Risk and Exploitability
The CVSS score of 8.1 classifies this flaw as a high‑severity risk. The EPSS score is not, so the likelihood of exploitation cannot be quantified from public data. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed public exploits at the time of analysis. The likely attack vector is remote network delivery of malicious JScript content, as the description indicates execution over a network. An attacker would need to embed malicious code that triggers the numeric conversion bug, which could lead to arbitrary code execution on the target system.
OpenCVE Enrichment