Impact
An integer overflow or wrap‑around flaw exists in the Windows Secure Kernel Mode. The flaw can be triggered by an authorized local attacker with some privileges, allowing the attacker to elevate their privileges to system level. This is an integer overflow weakness (CWE‑190) that can compromise confidentiality, integrity and availability of the affected system.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Microsoft Windows Server releases 2016, 2019, 2022 and 2025, including Server Core installations. The affected builds span x86, x64 and arm64 architectures.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, it is inferred that the attack vector is local: a privileged user who can execute code on the target machine may exploit the kernel integer wraparound to gain system‑level rights.
OpenCVE Enrichment