Impact
Missing authentication for a critical function in Windows Shell enables an authenticated user to elevate privileges locally, potentially allowing full control over the compromised system.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 (arm64 and x64 where applicable) and Microsoft Windows Server 2025, including Server Core installations.
Risk and Exploitability
With a CVSS score of 7.8 and no EPSS data, the risk is considered moderate high for local attackers; the vulnerability has not been listed in the CISA KEV catalog, and exploitation requires legitimate local access, so the attack surface is limited to environments where users have authorized credentials.
OpenCVE Enrichment