Impact
The vulnerability is a heap‑based buffer overflow in the Windows Power Dependency Coordinator component. An authorized user can exploit the flaw to overwrite memory on the heap, leading to a privilege escalation that allows local code execution with higher privileges than the original user.
Affected Systems
Several Windows client and server operating systems are impacted. Microsoft Windows 10 versions 1809, 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2 and 26H1, as well as Windows Server 2019, Server 2022, and Server 2025 (both full and Server Core) are all vulnerable according to the CNA product list.
Risk and Exploitability
The CVSS score for this vulnerability is 7.8, indicating a high severity local privilege escalation. The EPSS score is not available, and the issue is not currently listed in CISA's KEV catalog, suggesting that no widespread exploitation has been reported yet. The attack vector is local; an attacker who already has implicit access to the target system must trigger the overflow to gain elevated rights. Because the flaw resides in a privileged component, the potential impact is the compromise of the entire operating system if an attacker succeeds.
OpenCVE Enrichment