Impact
The flaw is a heap‑based buffer overflow within the Windows Defender Firewall Service, allowing an attacker with local credentials to gain elevated (administrator) rights. This vulnerability maps to CWE‑122, highlighting a classic memory corruption issue where improper bounds checking leads to privilege escalation.
Affected Systems
Affected are Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 along with their Server Core variants.
Risk and Exploitability
The CVSS score of 7 indicates medium‑to‑high impact. No EPSS score is provided, so the likelihood of exploitation cannot be quantified, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is local, requiring the attacker to possess a user account that can run the firewall service. Successful exploitation grants administrative privileges, enabling full control of the host and the potential to compromise other systems on the network.
OpenCVE Enrichment