Impact
A heap-based buffer overflow exists in Windows Core Messaging which an authorized attacker can leverage to execute code with elevated privileges. The flaw is a classic buffer copy without boundary checking, classified as CWE-122. When exploited, the attacker gains local administrative rights, enabling full control over the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016, 2019, 2022, 2025, including Server Core installations. All variants listed in the advisory are vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks this issue as high severity. No EPSS score is available, and it is currently not listed in the CISA KEV catalog, but the lack of public exploitation data does not diminish the risk. The vulnerability requires an attacker to have local access to the target machine; therefore, compromise of a user account or malware executing with user privileges can trigger the overflow. Once triggered, arbitrary code can run with system rights, leading to complete takeover of the local system. The likely attack vector is a local client process that interacts with Core Messaging, making the flaw exploitable by any scheduled task, service, or malicious user application running on the host.
OpenCVE Enrichment