Impact
A heap-based buffer overflow exists in the Windows SMB Client that can be triggered by an authorized local attacker. The flaw allows the attacker to execute arbitrary code at higher privilege levels, effectively granting administrative rights and full system control. This weakness corresponds to CWE-122.
Affected Systems
The affected product is Microsoft Windows 11 version 26H1, 64‑bit releases, as indicated by the provided CPE string. Users running this version should confirm whether the SMB client component is installed and active.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. No EPSS score is available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Successful exploitation requires local authorization, making the threat primarily relevant to insiders or compromised local accounts. If exploited, an attacker could gain unrestricted access to the system, jeopardizing confidentiality, integrity, and availability.
OpenCVE Enrichment