Impact
The vulnerability is a heap-based buffer overflow in the Windows Error Reporting service. When triggered by an authorized local attacker, the overflow allows the attacker to execute arbitrary code with the privileges of the service, leading to elevation of privilege on the affected system. The flaw is classified as CWE‑122 and delivers high severity as reflected by a CVSS score of 8.8, indicating significant potential damage if exploited.
Affected Systems
Windows 10 build 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025. These include both regular and Server Core editions.
Risk and Exploitability
Because the vulnerability requires local authorization, the attack surface is limited to users with existing access privileges. No EPSS score is available in the data, but the high CVSS rating and the lack of a KEV listing suggest that active exploitation is not currently widespread. Nevertheless, any local user who can invoke the Windows Error Reporting flow may be able to run arbitrary code and subsequently obtain elevated rights, posing a serious threat to system integrity.
OpenCVE Enrichment