Impact
An out‑of‑bounds read in the Windows Event Logging Service permits an unauthenticated attacker to execute arbitrary code. The flaw stems from mishandled buffer bounds (CWE-122 and CWE-125), allowing the attacker to craft malicious data that causes the service to read beyond allocated memory, leading to code execution on the host. The attack can be launched remotely over the network without user interaction.
Affected Systems
Microsoft Windows 10 releases from Version 1607 through 22H2, Windows 11 releases from 23H2 to 26H1, and Windows Server 2012 through 2025—including Server Core installations—are affected. All listed builds are vulnerable to the Event Logging Service flaw.
Risk and Exploitability
The CVSS base score is 9.8, indicating critical severity. EPSS is not available, so current exploit likelihood is uncertain, but the flaw permits remote code execution and is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability over the network, likely using RPC or event channel traffic. Because the flaw is remote and unauthenticated, any host exposing the Event Logging Service to untrusted networks faces high risk.
OpenCVE Enrichment