Impact
The vulnerability is an absolute path traversal in Windows Error Reporting, which permits a locally authenticated attacker to gain elevated privileges on the system. This flaw exploits a flaw in the way Windows processes error reports, allowing the attacker to override critical security boundaries. The weakness is classified as CWE-36, indicating a failure to properly restrict operations to a designated directory structure.
Affected Systems
Affected systems include Microsoft Windows 10 from version 1607 through 22H2, Microsoft Windows 11 from version 23H2 through 26H1, and Windows Server releases 2012 to 2025, across x86, x64, ARM64, and server core configurations. All listed builds are impacted by the path traversal flaw.
Risk and Exploitability
The CVSS score of 7.8 places this issue in the high severity range, underscoring the ability to bypass local security controls. Although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog, suggesting no known widely distributed exploits at this time. Based on the description, it is inferred that the attacker must have local authenticated access to manipulate error report paths, and by exploiting this path traversal, can elevate privileges to SYSTEM. The risk is therefore significant for users who operate with elevated or administrator privileges in the affected Windows environments.
OpenCVE Enrichment