Impact
The vulnerability is a use‑after‑free bug in the Windows DWM Core Library that allows an authorized local attacker to elevate privileges. This flaw is a memory corruption issue consistent with CWE‑416: Use After Free.
Affected Systems
The flaw targets Microsoft Windows 10 from version 1607 through 22H2, Windows 11 from 23H2 through 26H1, and Windows Server editions from 2012 to 2025, covering both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires a local, authorized attacker to trigger the use‑after‑free, resulting in elevated privileges that could be used for further system compromise.
OpenCVE Enrichment