Impact
A heap‑based buffer overflow exists in the Windows Credential Providers component, permitting an attacker who can send crafted input over a network to execute arbitrary code with the privileges of the credential provider process. The flaw arises when malformed credential data is processed, overflowing a heap buffer and enabling control over the affected system. This vulnerability is a classic example of CWE‑122, resulting in complete loss of confidentiality, integrity, and availability for the compromised host.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2 and 26H1, and Windows Server 2025—including Server Core installations—are affected. The issue is present on ARM64 for the 24H2 and 25H2 releases and on x64 for 26H1, while the Server 2025 target is platform‑agnostic as listed.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity. EPSS data is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nevertheless, the flaw is exploitable by an authorized user who can reach the Credential Provider over the network and supply malicious data. Successful exploitation would grant the attacker full control of the affected system. Given the high CVSS and the lack of a public exploit, the risk remains significant and warrants immediate mitigation.
OpenCVE Enrichment