Impact
A use‑after‑free flaw exists in Windows Universal Plug and Play Device Host that allows an unauthorized attacker to execute code locally. The vulnerability gives the attacker control to run arbitrary binaries with the same privileges as the service.
Affected Systems
The flaw affects Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 22H3, 23H2, 24H2, 25H2, and 26H1; and Windows Server 2012 through Windows Server 2025, including all core and standard installations for the listed versions.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is not available. An attacker would need to deliver crafted UPnP traffic to the vulnerable service, typically requiring local or network access. While there is no publicly available exploit code, the nature of the flaw means that exploitation is feasible if an attacker can reach the service, resulting in moderate to high risk for affected systems.
OpenCVE Enrichment