Impact
Based on the description, it is inferred that a use‑after‑free flaw in Windows App Installer can be triggered by an authorized attacker who runs a malicious application package, allowing the attacker to execute arbitrary code with higher privileges on the local system. This flaw, classified as CWE‑416, undermines local integrity by permitting code execution beyond the intended user context.
Affected Systems
Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1 as well as Windows Server 2025, including the Server Core installation, on both ARM64 and x64 architectures are impacted.
Risk and Exploitability
Based on the description, the likely attack path could be local, requiring a user who has the ability to install or run a malicious package. Once the use‑after‑free condition is satisfied, the attacker could bypass standard access controls and execute code as SYSTEM. The CVSS score of 7 marks the vulnerability as high severity, yet the potential to gain SYSTEM-level privileges locally poses a significant risk. The EPSS score is under 1%, indicating limited current exploitation activity, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment