Impact
The vulnerability in Windows Error Reporting stems from a directory that is written to with insecure permissions. An attacker who has valid local access can create a temporary file within that directory, enabling modification of error report data. The impact is limited to the local system and equals the ability to tamper with error reporting information, potentially skewing diagnostics or disabling useful error reporting features. The weakness is classified as CWE‑379, which addresses insecure file or directory permissions that allow unauthorized modification of the application state.
Affected Systems
Affected by Microsoft include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2016, 2019, 2022, and 2025 across both standard and Server Core installations. Users of these operating systems should verify whether they are running any of the listed releases and check for available updates that address the insecure permissions issue.
Risk and Exploitability
The CVSS score is 7.1, indicating a moderate to high severity, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires local authorized access, the risk to remote or anonymous attackers is reduced; however, malicious insiders or software installers with elevated privileges could exploit the flaw. The known weakness does not provide a straightforward path to remote code execution; instead, it grants the attacker the ability to alter the contents of temporary files used by the error reporting subsystem, which could affect system troubleshooting and stability.
OpenCVE Enrichment