Impact
The vulnerability is a heap-based buffer overflow located within the Windows Hello authentication component. The flaw allows an attacker who already has local access to execute code with elevated privileges, potentially taking full control of the affected system. The weakness is listed as CWE-122, which represents a classic buffer overflow scenario that can overwrite critical memory structures and subvert control flow.
Affected Systems
Microsoft Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 23H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1. No specific sub‑version or patch level is provided, but all listed operating system release streams are indicated as impacted.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity vulnerability. Because the attack vector is local (an authorized attacker), an exploiter must already have some level of system access, but can otherwise abnormally elevate to full administrative rights. The EPSS score is unavailable, making it unclear how frequently the flaw has already been seen in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. The likely exploitation path would involve invoking a crafted Windows Hello session or message that triggers the buffer overflow, but these details are not fully documented in the description. Given the absence of an official fix or public workaround, users should treat this as a critical local privilege escalation risk.
OpenCVE Enrichment