Impact
This vulnerability is a use‑after‑free flaw in the Desktop Window Manager that lets an authorized local attacker gain elevated privileges on the host system, potentially allowing them to execute code with higher rights.
Affected Systems
Affected systems include various versions of Microsoft Windows, including Windows 10 1607 through 22H2, Windows 11 23H2 through 26H1, and a range of Windows Server editions from 2012 to 2025, as well as their Server Core installations.
Risk and Exploitability
The flaw has a CVSS score of 7.8, indicating high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring an authorized user to invoke a manipulated window or process that triggers the use‑after‑free. While no public exploit is reported, the high score and local nature suggest a moderate probability of exploitation by attackers already on the target machine.
OpenCVE Enrichment