Impact
The vulnerability manifests as a heap‑based buffer overflow within the Windows Hello component. An attacker who can execute code in a local context can exploit this flaw to gain higher privileges on the host. The underlying weakness is a classic buffer overflow (CWE‑122), which undermines the integrity of the authentication subsystem and enables the attacker to execute arbitrary code with escalated rights.
Affected Systems
Microsoft products are affected, including Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2019, both standard and Server Core installations. The specific affected builds are listed in the CNA vendor/product details.
Risk and Exploitability
The CVSS base score of 8.2 reflects high severity, and the absence of an EPSS score means the exploitation probability is currently unknown but the risk remains significant. The flaw requires local, authorized execution, indicating that a privileged or able-to‑install-malware user could trigger the buffer overflow. Because the vulnerability is not included in the CISA KEV catalog, known exploitation in the wild is not documented, yet the high CVSS indicates diligence is warranted.
OpenCVE Enrichment