Impact
This vulnerability is a heap‑based buffer overflow in Windows Schannel that allows an attacker to execute arbitrary code on an affected system over the network without any authentication.
Affected Systems
Affected systems include Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2022 and Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, yet the nature of the flaw—remote code execution through a heap overflow—raises significant risk. The likely attack vector is remote network traffic sent to the Schannel component, which can lead to full system compromise if exploitation succeeds.
OpenCVE Enrichment