Impact
A use-after-free bug within the Windows 11 kernel can be triggered by a local, authorized user. This flaw allows the attacker to execute arbitrary code with SYSTEM privileges, effectively elevating from a regular user to administrator or full system control. This high‑severity flaw provides an attacker with SYSTEM privileges, enabling full control of the system.
Affected Systems
Microsoft Windows 11, version 26H1. No earlier releases or variations are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation risk. The EPSS score of less than 1% suggests an extremely low probability of exploitation at present, and the vulnerability is not in the CISA KEV catalog, meaning no confirmed active exploits. The exploit vector is local; an attacker must have authorized access or be able to run code as a legitimate user on the target machine to initiate the use‑after‑free and achieve privilege escalation.
OpenCVE Enrichment