Impact
The vulnerability stems from an untrusted pointer dereference in Windows Secure Kernel Mode. An attacker with some level of system access can exploit this flaw to gain elevated local privileges, potentially allowing full control over the affected machine. The weakness corresponds to CWE-822, which involves failures in handling untrusted input.
Affected Systems
The flaw affects Microsoft Windows 11 version 26H1 on x64 architecture. No other vendor or product is listed as affected at this time.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. With no EPSS value available and the vulnerability not listed in CISA KEV, the overall risk remains high yet lacks publicly confirmed exploitation data. The likely attack vector is local, requiring the attacker to already have authenticated access to the system to reach the vulnerable code.
OpenCVE Enrichment