Impact
The vulnerability is a heap-based buffer overflow located in Windows Connected User Experiences and Telemetry. Exploiting the overflow allows an attacker who has already gained some level of access to elevate their privileges. The flaw can result in privilege escalation rather than denial of service or other types of impact. The weakness is identified as CWE‑122, indicating that improper bounds checking when handling heap memory leads to the overflow.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Windows Server 2019, 2022, and 2025, including Server Core installations. These versions are affected as listed by the CNA.
Risk and Exploitability
The CVSS score of 8 indicates a high severity, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting that documented exploitation may be limited. The likely attack vector is through network communication, as the description states the elevation can occur over a network. An authorized attacker, meaning one who has some level of legitimate access or can masquerade as such, can orchestrate the exploit to gain higher privileges. The absence of an exploitation probability metric means that while the flaw is severe, the likelihood of a broad exploit remains uncertain based on available data.
OpenCVE Enrichment