Impact
A heap‑based buffer overflow in Windows Secure Kernel Mode allows an attacker who already has local access to gain higher privileges. The flaw, classified as CWE‑122, enables a malicious process to overwrite memory in a way that can elevate the attacker's user rights to that of the system or other privileged users.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The vulnerability scores a CVSS v3.1 of 8.2, indicating a high severity. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local exploitation by an authorized user; the attacker must execute crafted code in a process running with local privileges to trigger the buffer overflow and obtain elevated rights.
OpenCVE Enrichment