Impact
The vulnerability is an incorrect authorization check in the Windows Win32K kernel component. An attacker who already has local access can exploit this flaw to gain elevated privileges on the affected system. This allows the attacker to perform actions with higher privileges, potentially affecting the confidentiality, integrity, or availability of the machine.
Affected Systems
Affected systems include Windows 10 releases from version 1607 to 22H2, Windows 11 releases from 23H2 to 26H1, and Windows Server editions 2012 through 2025, including Server Core installations, as listed by Microsoft.
Risk and Exploitability
The CVSS score of 7 indicates a moderate to high severity for local privilege escalation. No EPSS data is available and the vulnerability is not currently listed in the CISA KEV catalog, implying no confirmed exploitation in the wild. The likely attack vector requires local access; once achieved it can convert a low‑privileged user into a privileged user, bypassing normal isolation controls.
OpenCVE Enrichment