Impact
A double free vulnerability in the Windows Rich Text Edit control allows an authorized local attacker to elevate privileges. The flaw enables memory deallocation errors that can be exploited to obtain higher rights on the host machine. The weakness is classified as CWE‑415, improper deallocation of heap resources.
Affected Systems
The flaw impacts a range of Microsoft Windows operating systems: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, and the 23H2 edition. All affected editions contain the vulnerable Rich Text Edit control.
Risk and Exploitability
The CVSS score of 6.7 reflects moderate severity. The EPSS score indicates a probability of less than 1 % for exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must have local access and the ability to trigger the Rich Text Edit control, so the attack vector is local via crafted RTF files. Exploitation requires that the attacker successfully induces a double free, thereby escalating privileges.
OpenCVE Enrichment