Impact
Based on the description, it is inferred that the CVE originates from a heap‑based buffer overflow within the Windows Online Certificate Status Protocol (OCSP) subsystem. The overflow can be triggered by a maliciously crafted OCSP response, enabling a locally‑authorized attacker to execute arbitrary code and elevate privileges on the affected Windows host. The weakness falls under CWE‑122, indicating memory corruption that permits overwriting of critical heap data.
Affected Systems
Affected products include Microsoft Windows 10 Version 1607 and Version 1809, as well as multiple server editions: Windows Server 2012 and the Server Core installation, Windows Server 2012 R2 with Server Core, Windows Server 2016 (including Server Core), Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 with Server Core. All listed versions are vulnerable until the patch is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7, signifying high severity for local privilege escalation. No EPSS data is currently available, and the issue is not yet listed in CISA’s Known Exploited Vulnerabilities catalog, suggesting that widespread exploitation may not yet be documented. An attacker must first have some form of authorized local access to the machine; from that position, the buffer overflow grants the attacker the ability to gain higher privileges, potentially entire administrative control over the system. Given the lack of remote exploitation vectors, the risk remains confined to environments where malicious parties can operate locally or leverage compromised user accounts.
OpenCVE Enrichment