Impact
The flaw is a use‑after‑free in Microsoft printer driver code that can be triggered by an authorized user on the local machine. When the vulnerable driver frees an object and then accesses it again, an attacker can overwrite data and execute arbitrary instructions with the privileges of the user process. As a result, the local user can gain higher privileges or otherwise execute code at a level they did not originally possess.
Affected Systems
Affected are Microsoft Windows 11 versions 24H2, 25H2, and 26H1 (x64) and Microsoft Windows Server 2025, including Server Core installations. The vulnerability applies to the default printer driver components shipped with those operating system releases.
Risk and Exploitability
The CVSS base score is 7.8, indicating a high severity, while the EPSS score is less than 1%, suggesting a very low likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog. It is a local privilege escalation vector requiring the attacker to be an authenticated user on the target system. Based on the description, it is inferred that a typical attack path may involve manipulating a print job or loading malicious content to trigger the use‑after‑free run code with the same or higher rights as the user, potentially compromising the system.
OpenCVE Enrichment