Impact
This vulnerability is an out‑of‑bounds read in the Windows Win32K subsystem that enables an authorized local user to read memory beyond the intended range, potentially allowing the user to gain elevated privileges on the system. The weakness is identified as CWE‑125 and can result in the attacker obtaining higher level access within the operating system, thereby compromising confidentiality, integrity, and availability of system resources. The exploitation is confined to local attacks that require user presence, but it can be leveraged to compromise the entire host if the attacker can elevate to full administrative power.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations). All listed operating systems run either 32‑bit or 64‑bit architectures and are affected by the Flaw.
Risk and Exploitability
The CVSS score of 7 indicates a medium to high severity for local privilege escalation. There is no EPSS score available, so exploitation likelihood cannot be quantified, and the vulnerability is not included in the CISA KEV catalog. Attackers require a legitimate user session and must be able to trigger the Win32K out‑of‑bounds read to gain elevated privileges; the impact is therefore limited to machines under local user operation but can lead to full system compromise if the attacker achieves administrative rights.
OpenCVE Enrichment