Impact
The vulnerability involves an untrusted pointer dereference in Windows Secure Kernel Mode, enabling an authorized local attacker to gain higher privileges. This flaw is categorized as CWE-822, representing improper handling of an untrusted pointer. Successful exploitation allows the attacker to execute code with elevated Windows kernel privileges, potentially compromising system integrity and confidentiality.
Affected Systems
Affected releases include Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server 2022 and 2025. The vulnerability is present on x86, x64, and ARM64 architectures as applicable, as reflected in the associated CPE entries.
Risk and Exploitability
The CVSS score of 7 indicates high impact, but the EPSS score is not available, so an exact exploitation probability cannot be estimated. The vulnerability is not listed in CISA KEV, suggesting no publicly known exploits yet. The likely attack vector is a local attacker who can run code within the user context to trigger the untrusted pointer dereference, thus requiring privileged user compromise or malicious code injection for exploitation.
OpenCVE Enrichment