Impact
A heap-based buffer overflow in Windows Management Services permits an authorized attacker to elevate privileges over a network. The vulnerability is a buffer overflow (CWE-122) that leads to privilege escalation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 8.8 denotes a high severity level. No EPSS score is currently available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, an attacker must have network access and some level of authorization to the Windows Management Services. Exploitation would involve triggering the buffer overflow through crafted network packets or service calls, potentially allowing the attacker to gain elevated privileges on the host.
OpenCVE Enrichment