Impact
The vulnerability is a classic use‑after‑free bug in the Windows Common Log File System Driver. When the driver later accesses a freed memory reference, an attacker with authorized local access can exploit the corrupted handle to execute code with higher privileges, effectively turning a low‑privilege account into an administrator. The weakness corresponds to CWE‑416 memory corruption.
Affected Systems
Microsoft Windows 11 versions 24H2 and 25H2 on arm64, Windows 11 version 26H1 on x64, and Microsoft Windows Server 2025 including Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers with local authorized access—such as a standard user who can interact with the device driver—can trigger the use‑after‑free to gain elevated privileges. The risk is therefore a significant local privilege escalation risk when the flaw remains unpatched.
OpenCVE Enrichment