Impact
A heap-based buffer overflow exists in the Windows HID class driver that permits an attacker with local system access to execute code with elevated privileges. The description indicates that the vulnerability involves the processing of HID reports, but the exact malformed report mechanism is not explicitly detailed; it is inferred that malformed HID reports could trigger the overflow. The likely attack vector is a local user interacting with the HID driver. The impact is an escalation of privileges rather than a denial of service or remote compromise; however, the flaw permits the attacker to install malware, modify system settings, or access confidential data that requires administrative rights.
Affected Systems
The vulnerability affects Microsoft Windows operating systems from Windows 10 version 1607 through 22H2, Windows 11 versions from 23H2 to 26H1, and multiple Windows Server releases including 2012 (full and core), 2012 R2, 2016, 2019, 2022, and 2025. All affected builds, regardless of CPU architecture (x86, x64, ARM64), are susceptible because the HID driver implementation is shared across these editions.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity due to local privilege escalation and non‑exploitable remotely. The EPSS score is not available, so no quantitative estimate of active exploitation probability is provided. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation. The attack requires local, authenticated access to the affected system, limiting its reach to environments where an attacker can gain physical or high‑privilege access. Once the buffer overflow is triggered, the attacker can take full administrative control of the machine.
OpenCVE Enrichment