Microsoft Windows Server 2025
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*
A vulnerability allowing local elevation of privilege has been identified in the Windows Advanced Rasterization Platform (WARP). This issue arises from integer size truncation, which can be exploited by an unauthorized attacker to gain elevated privileges on the system.
Exploitation of this vulnerability could allow an attacker to gain SYSTEM privileges.
To exploit this vulnerability, an attacker could create malicious WebGL content that triggers an unsafe buffer copy inside the Direct3D 10 WARP component. When a user processes this content in a Chromium-based browser, the manipulated parameters can cause a buffer overflow in the Windows graphics system, potentially leading to unauthorized privilege escalation.
Users can apply the security update provided by Microsoft to address this vulnerability. This security update is available through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.