Impact
This vulnerability is an out‑of‑bounds read in the Windows Win32K graphics subsystem. An authorized attacker with network‑level access can read invalid memory on the target system and use the resulting condition to gain higher privileges. The flaw is identified by CWE‑121 (Stack Based Buffer Overflow) and CWE‑125 (Out‑of‑Bound Read). The impact is an elevation of privilege for the attacker, allowing execution with higher privileges than the original account.
Affected Systems
The affected products include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2019, 2022, and 2025 (including Server Core installations). The specific versions are listed in the CNA affected list.
Risk and Exploitability
The CVSS score of 8 indicates high severity. The EPSS score is <1%, showing a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The CVE description indicates the attack vector is a network‑based authorized attacker, meaning an attacker with some degree of local or remote user privileges can exploit the flaw. Because no publicly available exploit has been disclosed, the risk remains based on the severity and the potential for advanced threat actors to develop custom exploits.
OpenCVE Enrichment