Impact
The disclosed flaw is an untrusted pointer dereference within the Windows SCSI Class system file, a CWE-822 weakness. By sending a specially crafted SCSI request from physical hardware, an attacker with on‑site access can cause the system to dereference an invalid pointer, leading to local privilege escalation and potentially full control over the target machine.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025 (including Server Core installations). All listed releases are affected by the SCSI Class system file flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.8, reflecting moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires physical access to the target machine and interaction with a SCSI controller, meaning an attack must be on‑site or have direct access to the hardware. Exploitation would involve triggering the pointer dereference through a crafted SCSI request to achieve privilege escalation.
OpenCVE Enrichment