Impact
The vulnerability is a heap‑based buffer overflow (CWE‑122) in Windows Credential Guard. An authorized local user can trigger the overflow to elevate privileges on the affected system, enabling the execution of code with higher rights.
Affected Systems
Affected vendors include Microsoft. Vulnerable products are Windows 10 version 21H2 and 22H2, and Windows 11 versions 23H2, 24H2, 25H2, and 26H1. The affected architectures are x86 and x64 for Windows 10 and arm64 and x64 for Windows 11.
Risk and Exploitability
The CVSS score of 7.0 indicates medium severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation likelihood is uncertain. The attack vector is local and requires authorized access; once the overflow is triggered, the attacker can elevate privileges to higher user rights, potentially compromising system integrity depending on subsequent actions.
OpenCVE Enrichment