Impact
The vulnerability is a heap‑based buffer overflow in the Local Security Authority Server (lsasrv) component. A local attacker who is already authenticated to the system can trigger the overflow to gain elevated privileges. This flaw is classified as CWE‑122 and CWE‑190, allowing the attacker to potentially execute arbitrary code with higher privileges. The reach of the compromise is limited to the local machine but can lead to complete system takeover if the privilege escalation succeeds.
Affected Systems
Affected builds include Microsoft Windows 11 24H2, Windows 11 25H2, and Windows 11 26H1, as well as Windows Server 2025 (including Server Core installations). The affected architectures are ARM64 for the 24H2 and 25H2 releases and x64 for the 26H1 release; Windows Server 2025 encompasses both common AMD64 architectures.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, and the vulnerability requires a local, authenticated attacker to exploit it. No exploitation probability data is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting there are no confirmed public exploits yet. Nevertheless, because it permits unilateral privilege escalation on a compromised host, the risk is significant for environments where local access cannot be tightly controlled, and patching is recommended before any potential exploitation scenario arises.
OpenCVE Enrichment