Impact
An untrusted pointer dereference within the Windows Group Policy subsystem allows an attacker who has authorized network access to elevate privileges on the target system. The flaw arises when malicious or corrupted group policy data is processed, exposing the system to an out‑of‑bounds memory access that can be leveraged to gain higher authority. With sufficient privileges, the attacker can modify system configuration or install additional malware, thereby compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability impacts Microsoft Windows client and server products including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and all Windows Server releases from 2012 through 2025, covering both standard and Server Core installations.
Risk and Exploitability
The CVSS severity score of 8 indicates a high risk, while the EPSS score is not yet available. The weakness, documented as CWE-125, CWE-822, and CWE-843, can be exploited by an attacker who can supply or alter group policy data over the network. Once triggered, it may allow the attacker to raise local privileges. The vulnerability is not currently listed in the CISA KEV catalog, but the lack of public exploitation does not mitigate the high risk posed by the potential for privilege escalation. The attack path requires network bandwidth to supply malicious policy information and an authenticated account capable of influencing group policy.
OpenCVE Enrichment