Impact
The flaw is a double free error within Windows Projected File System, a core operating‑system component. After memory is freed twice, an attacker with local execution rights can direct the program’s flow to arbitrary locations, enabling them to gain higher privileges. This weakness aligns with CWE‑415 and leads to privilege escalation rather than remote code execution or denial of service.
Affected Systems
The vulnerability affects Windows 10 releases 1809, 21H2 and 22H2; Windows 11 releases 22H3, 23H2, 24H2, 25H2 and 26H1; and Windows Server 2019, 2022, 2025, as well as the 23H2 Server core installation. All processor families supported by Microsoft (x86, x64, ARM 64) are impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for local attackers who can run code that triggers the double free. No estimate of the probability of exploitation is available. The flaw is not listed in the CISA catalog of known exploited vulnerabilities. Exploitation requires a user with authorized or local system access; remote exploitation without such access is not documented.
OpenCVE Enrichment