Impact
The vulnerability is a stack‑based buffer overflow in the Microsoft Graphics Component that allows a local user with authorized privileges to execute arbitrary code with elevated rights. This flaw, classified as CWE‑121, can be leveraged to gain complete control over the affected system, potentially compromising all data and services running under that user’s session.
Affected Systems
The flaw affects Microsoft Windows 10 versions 21H2 and 22H2, and Windows 11 versions 23H2, 24H2, 25H2, and 26H1.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. While the EPSS score is not available, there is no evidence that this vulnerability is currently in the CISA KEV catalog. The attack vector is local: an attacker who can run code on the machine, but does not require network access. Successful exploitation would allow privilege escalation to local administrator or higher and is therefore considered a serious risk for any machine that has not been patched.
OpenCVE Enrichment