Impact
The Windows Program Compatibility Assistant Service contains a flaw where special elements in command construction are not properly neutralized. An attacker who can execute commands locally can inject arbitrary arguments into the service’s command line, allowing execution with the service’s elevated privileges. This results in local privilege escalation that can compromise system integrity and confidentiality. The weakness aligns with CWE-77.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server 2016 (both standard and Server Core), 2019 (both standard and Server Core), 2022, and 2025 (both standard and Server Core).
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the EPSS score is not available, so the exploitation likelihood cannot be quantified from public data. The vulnerability is not currently listed in the CISA KEV catalog, implying no documented active exploitation, but the local nature of the attack means that an authenticated or otherwise authorized user could potentially elevate privileges. Based on the description, the likely attack vector is a local privileged user or process that can interact with the Program Compatibility Assistant Service.
OpenCVE Enrichment