Impact
A heap‑based buffer overflow exists in the Windows Enterprise App Management component, enabling an attacker who already has authorized access to raise privileges on the local system. The vulnerability is a classic example of an unchecked bounds condition (CWE‑122). As such, an attacker can gain higher rights to read, modify, or execute code with elevated privileges after exploiting the flaw, potentially allowing full control over the affected machine.
Affected Systems
Affected products include Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from version 23H2 up through 26H1, and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core variants). These versions are listed by Microsoft as susceptible to the vulnerability.
Risk and Exploitability
The CVSS score of 8.0 classifies this as high severity. The EPSS score of < 1% indicates a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based, as the flaw permits privilege escalation over a network for an authorized attacker. Exploitation would require the attacker to have legitimate access or a foothold in the network where the Windows Enterprise App Management service is active; no external credentials or elevated rights are required beyond that authorization.
OpenCVE Enrichment