Impact
The vulnerability is a heap‑based buffer overflow in the Windows Kerberos service that allows an attacker with local access to construct malicious requests. If exploited, the attacker can attain higher privileges on the host, enabling arbitrary code execution with elevated rights. The likely attack vector is a local user or process that can interact with the Kerberos service; this inference is drawn from the specification that an "authorized attacker" can elevate privileges locally. The flaw is classified as CWE‑122 and has a CVSS score of 7.8, indicating a high severity local privilege escalation with significant impact on confidentiality, integrity, and availability.
Affected Systems
Affected systems include Microsoft Windows 10 versions ranging from 1607 to 22H2, Windows 11 iterations 23H2 through 26H1 (including ARM64 and x64 platforms), and Windows Server releases from 2012 up to 2025 (both full and server core installations).
Risk and Exploitability
The CVSS score of 7.8 reflects substantial risk when an attacker can execute code locally. No EPSS score is provided and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known exploits yet. However, because the flaw requires only local or authorized access, an adversary with such foothold could elevate privileges immediately. Organizations with privileged access controls and least‑privilege enforcement remain at higher risk until the patch is applied.
OpenCVE Enrichment