Impact
The vulnerability arises from the deserialization of untrusted data within the Windows IP Address Management (IPAM) Service An attacker who is already authorized on the local system can supply crafted input that bypasses normal safeguards, allowing the service to execute code or elevate privileges. Because the flaw permits escalation to higher privileges locally, a user could potentially gain full system access, compromising confidentiality, integrity, and availability of the affected machine. The weakness is formally identified as CWE-502, which covers insecure deserialization.
Affected Systems
The flaw affects a wide range of Microsoft Windows releases. Specifically, Windows 10 versions 1607, 1809, 21H2, and 22H2, as well as Windows 11 editions 23H2, 24H2, 25H2, and 26H1, all on x86, x64, and ARM64 hardware. In addition, Windows Server 2016, 2019, 2022, and the upcoming 2025 releases—including their Server Core installations—are vulnerable. All affected builds rely on the same IPAM Service component, which is present in both desktop and server variants.
Risk and Exploitability
The CVSS score of 7 classifies this vulnerability as High, indicating that exploitation could have a substantial impact. The EPSS score is 2%, suggesting that while the probability of exploitation is low, it still exists. The flaw requires only local access and does not expose itself to remote attackers, which limits the attack surface. The service runs with sufficient privileges to affect the whole system, so an authorized user who can trigger the deserialization path can elevate their rights, effectively gaining full control. Because the flaw is local only, mitigation hinges on applying the vendor patch and restricting who can use the IPAM service.
OpenCVE Enrichment