Impact
Windows Core Messaging includes a type‑confusion bug that allows an authorized local user to access resources with an incompatible type. This flaw can be leveraged to elevate privileges on the affected system. The vulnerability is documented as CWE‑843, which denotes type confusion. The identified impact, therefore, is that a local attacker may gain higher privileges and potentially execute code with elevated rights or compromise additional services.
Affected Systems
The flaw affects multiple Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and the server editions Windows Server 2016, 2019, 2022, 2025. Both full and Server Core installations are listed as impacted. All builds listed in the CNA information are considered vulnerable until patched.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for this local privilege escalation. No EPSS score is available, so the current exploitation probability is unknown, but the lack of detection in the CISA KEV catalog suggests limited known exploitation but a potentially high risk if the vulnerability is discovered. Because the flaw requires local authorization, the attack surface is restricted to users who already have local access, but once the bug is abused, privilege elevation could allow an attacker to gain full system control. The most likely attack vector is a local privileged user executing a malicious application that triggers the type‑confusion logic in Core Messaging.
OpenCVE Enrichment