Impact
The vulnerability is a heap-based buffer overflow in the Windows Error Reporting component that allows an attacker with local authority to elevate privileges on the system. Exploitation of this flaw can grant the attacker SYSTEM-level access, enabling arbitrary code execution and full control over the affected machine. The weakness is identified as a classic buffer overflow, CWE-122.
Affected Systems
Affected products include Microsoft Windows 10 (version 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Microsoft Windows Server 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for privilege escalation. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits at this time. The likely attack vector is local, requiring an authorized user or a user with the ability to execute code on the target. The lack of public exploits does not reduce the risk for organizations running the affected versions, as original exploitation would involve injecting oversized data into the Windows Error Reporting process to overflow the heap and gain elevated privileges.
OpenCVE Enrichment