Impact
Windows WalletService contains a use‑after‑free vulnerability that allows an attacker with local authorization to elevate privileges. Exploiting this flaw can grant the attacker higher rights, potentially enabling full control over the affected system. The weakness is classified as CWE‑416.
Affected Systems
The vulnerability affects Microsoft Windows Server editions 2016, 2019, 2022, 2025, and the 23H2 Edition, including Server Core installations.
Risk and Exploitability
The CVSS score is 7, indicating a high severity. EPSS is not available and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated on the host, and the attack vector is local.
OpenCVE Enrichment