Impact
Heap-based buffer overflow occurs in the Windows Network Connection Broker's handling of network connection data. An attacker who already has local user access can trigger the overflow by supplying a crafted network data structure, enabling the execution of code with elevated local privileges. The vulnerability is identified as CWE-122 and grants the attacker the ability to gain administrative rights on the affected machine, compromising confidentiality, integrity, and availability within that host.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations. All enumerated revisions are affected as listed by CNA.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity level. EPSS data is unavailable, so an exact exploitation probability cannot be quantified, but the lack of KEV listing suggests no public exploit yet. The likely attack vector is local, requiring an attacker to already gain a user session on the system. Once the overflow is triggered, privileged code execution is possible, allowing the attacker to modify system configurations, install malware, or exfiltrate data.
OpenCVE Enrichment