Impact
A heap‑based buffer overflow in the Windows Shell component enables an attacker who is not authenticated to execute arbitrary code remotely. The flaw allows the attacker to exploit a memory corruption bug and gain control of the target system without user interaction, leading to full compromise of confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as Critical, and the EPSS score of 1% indicates a low but non‑negligible exploit probability. It is not listed in the CISA KEV catalog. The likely attack path involves sending a crafted network packet to the Windows Shell service, which triggers the heap overflow and allows the attacker to inject and execute malicious payloads. Because the vulnerability is accessible from the network and does not require elevated privileges, it presents a high‑risk, remote attack vector that can compromise any affected system without local interaction.
OpenCVE Enrichment