Impact
An attacker with user‑level access can craft a Windows compressed folder that contains internally referenced paths designed to traverse beyond the intended directory. When the operating system processes this folder, the unwarranted path traversal is improperly limited, allowing the attacker to access privileged resources and execute code with elevated rights. This flaw is identified as a pathname traversal weakness (CWE‑22) and results in local privilege escalation, which can be leveraged to gain administrative control, install malware, or otherwise compromise the system.
Affected Systems
Affected systems include Windows 10 versions 1607 through 22H2, Windows 11 versions 23H2 through 26H1, and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both full and core installations. All listed builds—and architectures such as x86, x64, arm64—contain the vulnerability as indicated by the referenced CPE strings.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation vulnerability. EPSS data is not available, but the risk remains significant for any local user who can create or extract compressed folders. The vulnerability is not listed in the CISA KEV catalog, so no publicly documented exploitation is known, yet the potential for administrative gain remains high.
OpenCVE Enrichment