Impact
The vulnerability is a numeric truncation error in the Windows Kernel that enables an authorized local user to elevate privileges. The flaw is tied to CWE‑122 (Buffer Overflow) and CWE‑197 (Numeric Truncation). Once exploited, an attacker gains higher access rights on the affected system, potentially allowing full control of the machine or the ability to perform actions reserved for administrators.
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases from 2012 through 2025 (both standard and core installations). All listed versions are subject to the identified elevation of privilege issue.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires local, authorized access, meaning it is a local privilege escalation vector. An attacker who can log on to the target system can use the flaw to gain elevated rights, thereby compromising system confidentiality, integrity, and availability. No remote exploitation vector is known from the available data.
OpenCVE Enrichment