Impact
A heap‑based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem allows an authorized local user to elevate privileges. The flaw occurs when ALPC processes an invalid memory buffer and is identified as CWE‑122. The vulnerability is also related to the ALPC protocol, designated CWE‑908.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2 and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, and 2022, including both standard and Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. The EPSS score is 4 %, indicating a moderate probability of exploitation at this time. The vulnerability is listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must be an authorized local user with the ability to execute code; the likely attack vector is through local code execution. Consequently, the risk is significant for environments where local users can run arbitrary code, although widespread exploitation appears unlikely until a public exploit becomes available.
OpenCVE Enrichment