Impact
A heap-based buffer overflow in the Windows Program Compatibility Assistant Service allows an authorized local attacker to gain elevated privileges. This flaw corresponds to CWE-122 and could enable the attacker to execute arbitrary privileged code on the impacted machine.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2 as well as Windows 11 versions 23H2, 24H2, 25H2, and 26H1. Windows Server editions 2016 and 2019, both standard and Server Core installations, as well as Windows Server 2022 and 2025 (including Server Core) are also vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity vulnerability. Exploitation requires that the attacker already has local, authorized access to the system, meaning it is a local privilege escalation scenario. No known exploits are listed and it is not currently in the CISA Known Exploited Vulnerabilities catalog, but the lack of mitigation could allow a determined adversary to leverage the overflow to execute code with elevated rights on the compromised host.
OpenCVE Enrichment