Impact
The vulnerability is a stack‑based buffer overflow in the Windows Win32K component. It permits an authorized attacker with network access to elevate privileges, granting them higher levels of control on the affected system. This flaw is identified as CWE‑121, representing a buffer overrun that can compromise confidentiality, integrity, and availability by enabling unauthorized code execution at a higher privilege level.
Affected Systems
Affected Microsoft products include Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2019, 2022, and 2025 (both full and Server‑Core installations). The vulnerability applies to 32‑bit x86, 64‑bit AMD64, and ARM64 architectures as listed in the affected CPE entries.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity risk, and the EPSS score of <1% indicates a very low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, implying no known widespread attacks. Since the attack vector is network‑based and requires an authorized attacker, organizations should treat this as a potential remote privilege escalation scenario and apply mitigation promptly.
OpenCVE Enrichment