Impact
Untrusted pointer dereference occurs inside a Windows Virtualization-Based Security enclave, allowing a local or authorized attacker to elevate privileges locally. The flaw enables privilege escalation from a lower level to a higher privileged context, effectively bypassing the isolation intended by the Virtualization-Based Security feature. This is categorised as a classic Local Privilege Escalation weakness with CWE-822.
Affected Systems
Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2025 (including Server Core installations) are affected by the vulnerability.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact and moderate exploitation complexity for a local attacker. External Threat Probability (EPSS) is not available, so the likelihood cannot be precisely quantified; however, the vulnerability is not listed in CISA KEV, implying no known widespread exploitation. Access requires local, authorized roles, indicating that an insider or a compromised local account could exploit the flaw to gain elevated privileges.
OpenCVE Enrichment