Impact
An use‑after‑free flaw exists in the Windows DWM Core Library that allows an authorized local user to cause the kernel to execute code with higher privileges. This is a CWE‑416 vulnerability and can lead to arbitrary code execution and full control of the affected system by a local attacker.
Affected Systems
Microsoft products affected include Windows 10 versions 1809, 21H2, and 22H2; Windows Server 2019 (including Server Core); and Windows Server 2022. Version details are limited to the product listings provided in the CNA data; the vulnerability spans the operating systems listed in the known CPEs.
Risk and Exploitability
The CVSS score is 7.8 indicating a high severity, while the EPSS score is below 1 % and the vulnerability is not currently in the CISA KEV catalog. The exploit requires a local, authorized user to trigger the use‑after‑free condition, so remote exploitation is not supported according to the available data.
OpenCVE Enrichment