Impact
The vulnerability is a heap-based buffer overflow in the Windows NFS Portmapper component. The flaw can be triggered by an attacker who already has authorized local access and allows them to overwrite critical memory structures, thereby elevating privileges to a higher local level. Because the attack occurs locally, it may lead to the attacker gaining administrative rights on the host, enabling further exploitation or persistence.
Affected Systems
Affected are Microsoft Windows 10 from version 1607 through 22H2 (desktop editions) and Windows 11 from versions 23H2 through 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates substantial potential impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. The likely attack vector is a local authorized user exploiting the NFS Portmapper service; it requires that the service is running and that the user has sufficient privileges to invoke the vulnerable functionality.
OpenCVE Enrichment