Impact
A numeric truncation error in the Kerberos authentication routines allows an attacker with local access to elevate privileges. The flaw arises from improper handling of integer values during ticket validation, classified as CWE‑122 and CWE‑197. By forcing a truncation, the attacker can bypass checks that enforce privilege levels, thereby gaining administrative or SYSTEM rights on the compromised machine. The resulting loss of integrity can enable arbitrary code execution, modification of system settings, or access to sensitive local data.
Affected Systems
The vulnerability affects Microsoft Windows operating systems, specifically Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2019 (standard and Server Core), 2022, 2025. All listed builds are current releases for desktop and server platforms, and the affected components are the Kerberos authentication subsystem embedded in these OSes.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % shows a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attack requires local authenticated access to the target system; an attacker must trigger the numeric truncation during Kerberos ticket processing. Because the vector is local and constrained to a single machine, the risk to the broader network is limited, but the impact on the compromised endpoint is significant, allowing an attacker to compromise local integrity and confidentiality.
OpenCVE Enrichment