Impact
The vulnerability is a missing authorization check in the Windows Kernel that allows an authorized local user to raise their privileges to a higher level. This flaw permits a user with any valid local account to execute code with elevated rights, potentially compromising confidentiality, integrity, or availability of the system. The weakness is identified as CWE‑862 (Improper Authorization).
Affected Systems
Affected deployments include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2019, Server 2022, and Server 2025, including their Server Core installations.
Risk and Exploitability
The CVSS base score of 7.8 rates the vulnerability as high impact, but the attack vector is local. Based on the description, it is inferred that an attacker must already have local access to exploit the flaw. The EPSS score is not available, so the precise exploitation probability is unknown. The vulnerability is not yet listed in the CISA KEV catalog. Once elevated, an attacker could install malware, exfiltrate data, or pivot to other systems. The lack of authorization in the kernel enables this privilege escalation without network interaction, making it a significant local threat.
OpenCVE Enrichment