Impact
A heap-based buffer overflow exists within Windows Credential Providers that permits an adversary with local access to obtain higher privileges on the affected system. The flaw arises when the credential provider incorrectly handles user input, allowing a crafted payload to overwrite adjacent memory. Once an elevated privilege is achieved, the attacker can bypass security controls and execute arbitrary code, compromising the confidentiality, integrity, or availability of the system without the need for a remote attack vector.
Affected Systems
Microsoft Windows 10 Version 1809, Version 21H2, Version 22H2; Microsoft Windows 11 Versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2019, Server 2022, Server 2025 (including Server Core installations).
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a high-severity local privilege escalation risk. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The attack requires only local or authorized access to craft the payload; automated exploitation is unlikely at this time but the available buffer overflow flaw presents a clear path to privilege elevation if an attacker can execute it through the affected credential provider.
OpenCVE Enrichment