Impact
The vulnerability arises from a use‑after‑free condition in the Windows kernel, allowing an authorized local user to execute code with kernel privileges, effectively escalating privileges. The weakness is identified as CWE‑122. The impact is the ability for a local attacker to gain broad system control, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected releases include Windows 10 versions 1607, 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and the corresponding Server Core installations.
Risk and Exploitability
The CVSS score of 7.0 places the vulnerability in the high‑severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of analysis. The likely attack vector is a local, authenticated user exploiting the use‑after‑free to run code with elevated kernel rights.
OpenCVE Enrichment