Impact
A heap-based buffer overflow in the Windows Graphics Kernel permits an authorized user to execute arbitrary code locally on the affected Windows platforms. The flaw allows manipulation of kernel-space memory allocations and can lead to compromise of system integrity through locally–run code. It directly impacts confidentiality, integrity, and availability for any user with the ability to run code on the vulnerable machine.
Affected Systems
The vulnerability impacts Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including all Server‑Core installations. All supported hardware platforms (x86, x64, and ARM64) listed in the vendor guidance are susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the lack of an EPSS score or KEV listing suggests no widely documented exploitation yet. The attack vector is local; an attacker who can run code on the target machine can trigger the overflow. Successful exploitation would grant the attacker unrestricted local code execution, enabling full control over the system.
OpenCVE Enrichment