Impact
The vulnerability is an out-of-bounds read in the Windows CD‑ROM driver that permits an attacker who already has local user access to elevate privileges. The flaw allows improper memory access which the Microsoft update claims can be abused to grant higher privileges, potentially compromising the system fully when exploited locally.
Affected Systems
This issue affects Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2012 (Server Core and standard), Windows Server 2012 R2 (Server Core and standard), Windows Server 2016, Windows Server 2019 (Server Core and standard), Windows Server 2022, and Windows Server 2025 (Server Core and standard). The affected drivers are present in the listed operating system releases as identified by the corresponding CPE entries.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local privilege escalation. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that publicly known exploitation is not widespread yet. The attack vector is inferred to be local, requiring the attacker to have some level of authorized access to trigger the out-of-bounds read and elevate privileges, as explicitly stated in the description.
OpenCVE Enrichment