Impact
A heap-based buffer overflow in the Windows Error Reporting component allows an authorized attacker to elevate privileges over a network. The flaw occurs when the service processes error data and can lead to arbitrary code execution or privilege escalation. The weakness is a classic buffer overflow, linked to CWE‑122, enabling attackers to increase their authority on the target system. The main impact is the potential for an attacker to gain elevated rights, execute malicious code, or compromise the host’s integrity and confidentiality.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including all Server Core installations. These systems run the Windows Error Reporting service that is affected by the vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS score of 8, indicating high severity, but the EPSS score is not available and the issue is not listed in the CISA KEV catalogue. Based on the description, the likely attack vector is a network‑based interaction with the Windows Error Reporting service by an authorized user. While we lack public exploit evidence, the severity rating and nature of the flaw suggest a significant risk if the service is accessible from untrusted networks or if an attacker can locally exploit the component. The potential to elevate privileges can lead to full compromise, especially on machines where the service runs with SYSTEM privileges.
OpenCVE Enrichment