Impact
The heap-based buffer overflow occurs in the Winsock networking component, allowing an attacker with local access to overwrite adjacent memory and cause a memory corruption. That corruption can be used to execute arbitrary code with elevated privileges. The flaw is a classic allocation-based overflow (CWE-122), providing a mechanism for privilege escalation without requiring network exposure. Once exploited, the attacker can gain full control over the local system, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 in both full and Server Core installations. The vulnerability impacts both x86 and x64 architecture and various ARM64 builds as enumerated in the CNA data.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity. No EPSS score is currently available, and the vulnerability is not listed in CISA KEV, suggesting no widespread exploitation yet. Based on the description, the likely attack vector is local; an authorized user must engage a malformed Winsock call to trigger the overflow. Because privilege escalation requires local privileges as a starting point, exploitation is limited to environments where an attacker already has user-level access.
OpenCVE Enrichment