Impact
The vulnerability arises from missing authorization checks in the Data Sharing Service Client, enabling an attacker with local user credentials to gain elevated privileges on the affected Windows system. This is a local privilege escalation flaw classified as CWE‑862, allowing the attacker to perform actions that normally require higher administrative rights. The impact is limited to the local machine; there is no disclosure of sensitive data or remote code execution beyond privilege escalation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2016 (including Server Core), Windows Server 2019 (including Server Core), Windows Server 2022, and Windows Server 2025 (including Server Core).
Risk and Exploitability
The flaw carries a CVSS score of 7.8, indicating a high severity for a local privilege escalation with an attacker needing prior authorized access. EPSS data is not available, so the precise exploitation probability is unknown, but the lack of remote attack vector and the local nature of the exploit reduce the overall risk compared to remote vulnerabilities. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known public exploitation at this time. The likely attack path involves an authenticated user executing the Data Sharing Service Client with insufficient authorization checks, leading to execution of privileged functions that are otherwise restricted.
OpenCVE Enrichment