Impact
An untrusted search path in the Windows Smart Card component permits an authorized local user to execute code as a higher‑privileged account. The vulnerability arises when the Smart Card driver loads libraries from non‑system directories, allowing an attacker to replace a legitimate library with a malicious one and gain elevated rights without needing network‑level compromise. The weakness is classified as designated by CWE‑426, indicating unsafe management of paths to sensitive executables.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited known exploitation but still a significant risk for systems with users who have local Windows access. An attacker requires local user privileges to launch the exploit, and the attack vector is local. Successful exploitation results in elevation to administrative level, enabling further compromise of the affected system.
OpenCVE Enrichment