Impact
Use after free in the Universal Plug and Play Device Host component allows an attacker with local access to gain higher privileges on the affected Windows system.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 22H3, 26H1, and Windows Server 2012 through 2025, including both regular and Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. Exploitation requires a local attacker, and the exploit is based on a use‑after‑free condition that can be leveraged once the attacker can run a malicious process. Because the vulnerability is not yet listed in the CISA KEV catalog and no EPSS data is available, the likelihood of immediate public exploitation is unclear, but the potential for local privilege escalation remains significant.
OpenCVE Enrichment