Impact
This flaw is a heap‑based buffer overflow in the Windows kernel that lets an unauthenticated attacker execute arbitrary code after sending malicious data over a network connection. The lack of bounds checking allows the attacker to overwrite kernel memory, potentially compromising system confidentiality, integrity, and availability. The weakness is classified as CWE‑122.
Affected Systems
A broad set of Windows client and server releases are impacted. This includes Windows 10 releases 1607 through 22H2, Windows 11 releases 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, along with their server core variants. All architecture builds (x86, x64, arm64) that match the listed CPEs are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is currently unspecified, and the vulnerability has not yet been listed in CISA's KEV catalog. Attackers would need network connectivity to the target, and the exploitation would likely require the ability to send crafted packets to the kernel, which may be mitigated by firewalls or network segmentation. As the flaw permits remote code execution, the risk to affected deployments is high and remediation is strongly recommended.
OpenCVE Enrichment