Impact
A use‑after‑free flaw in Windows’ internal task bar can make an authorized local attacker execute code with elevated privileges. Based on the description, it is inferred that the flaw is triggered by manipulating task bar components, which leads to a local privilege escalation that exploits uninitialized memory use.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Microsoft Windows 11 versions 24H2, 25H2, and 26H1, and Microsoft Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation. The EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires local authenticated access and manipulation of the task bar; no public exploit is known at this time.
OpenCVE Enrichment