Impact
A heap‑based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem allows an authorized local user to gain elevated privileges. The flaw occurs when ALPC processes an invalid memory buffer, leading to corruption of kernel data that can be controlled by the attacker. This vulnerability is characterized as CWE‑122 (heap‑based buffer overflow) and involves the ALPC protocol (CWE‑908).
Affected Systems
Affected by this weakness are Microsoft Windows 10 variants released in version 1607, 1809, 21H2 and 22H2, as well as Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019 and 2022, including both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact. EPSS scores are not available, and the vulnerability is not listed in the CISA KEV catalog. Exposition requires a local, authorized attacker with the ability to execute code in the context of a user account; no remote or network‑based attack vector is disclosed. Consequently, the risk is significant for environments where local users can run arbitrary code, but the likelihood of widespread exploitation remains uncertain pending public exploit development.
OpenCVE Enrichment