Impact
The Windows Camera Frame Server Monitor contains a heap-based buffer overflow that permits an authorized local attacker to gain higher privileges by corrupting heap memory. The weakness, identified as CWE-122, arises in the way the service processes camera frame data and could allow an attacker to execute arbitrary code with elevated rights, thereby compromising system integrity.
Affected Systems
Affected vendors and products include Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation. The vulnerability spans the specified OS releases and any system deploying the Camera Frame Server Monitor service on these platforms.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation vulnerability, though the EPSS score is currently not available and the issue is not listed in CISA’s KEV catalog. The attack vector is local, requiring the attacker to have authorized access to the target machine and to trigger the heap overflow, likely through crafted camera data or similar interactions with the vulnerable service.
OpenCVE Enrichment