Impact
This vulnerability is a kernel‑level use‑after‑free flaw that permits a local attacker to gain SYSTEM privileges. The flaw arises when a freed kernel object is accessed before it is invalidated, and the attacker can drive the kernel into executing arbitrary instructions. The weakness is identified as CWE‑416 and is triggered only by local code execution.
Affected Systems
Affected releases include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2012 through 2025, including Server Core installations. The CVE list covers x86, x64 and ARM architectures, though no further sub‑version granularity is provided.
Risk and Exploitability
The CVSS score of 9.3 and an EPSS score of 2% indicate a high severity local exploitation risk with a low but non‑negligible probability of widespread attacks. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires that the adversary first achieve local code execution— for example, via a malicious driver or a user with the ability to execute arbitrary binaries—before exploiting the use‑after‑free to elevate privileges.
OpenCVE Enrichment