Impact
An untrusted pointer dereference within the Kernel Streaming WOW Thunk Service Driver can be exploited by an authorized local user to elevate privileges. This flaw permits a user with access to the driver to gain higher privileges on the system, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
The vulnerability affects Microsoft Windows 10 version 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Microsoft Windows Server 2025 (including Server Core installation).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that widespread exploitation evidence is currently lacking. However, because the flaw requires an authorized attacker with local access, the most likely attack vector is one where a user can load or interact with the vulnerable driver, potentially through application exploitation or social engineering. The risk is therefore moderate to high for environments where privileged local users exist and the driver is active.
OpenCVE Enrichment