Impact
The vulnerability is a trusted pointer dereference in the Windows Alternate Procedure Call (ALPC) subsystem, classified as CWE-822. An authenticated user can craft malicious ALPC packets that cause the kernel to dereference untrusted memory, allowing the attacker to elevate their privileges from a standard user to an elevated role such as administrator. This flaw does not grant remote access; it requires that the attacker already has local system presence.
Affected Systems
Microsoft Windows releases affected are Windows 10 Version 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases including 2019 (with and without Server Core), 2022, and 2025 (with and without Server Core).
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. EPSS information is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Inferred from the description, an attacker must already be authenticated on the host to exploit this flaw, meaning that an already present local threat actor could use the flaw to subvert local security and compromise the system.
OpenCVE Enrichment