Impact
The vulnerability is a heap‑based buffer overflow in the Windows Win32 Kernel Subsystem that allows an authenticated attacker with local privileges to write beyond allocated memory bounds. Exploitation can lead to elevation of privileges on the affected system, potentially giving the attacker full administrative rights. This weakness aligns with the classic buffer overflow identified by CWE‑122.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025. All listed build variants (x86, x64, arm64, Server Core) are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high risk. The EPSS score is < 1%, indicating a very low probability of exploitation. The nature of the heap overflow and its local execution model means an attacker who is already present on the machine can craft a payload to gain higher privileges. Unlike remote exploits, no network connectivity is required; the attacker must be authenticated to the target system. Penetration tests should include checks for Win32k privileged memory handling.
OpenCVE Enrichment