Impact
A use‑after‑free flaw in the DirectX graphics kernel can be triggered by an authorized local user, allowing the attacker to execute arbitrary code with higher privileges. This grants the attacker the ability to compromise system files, registry entries, or other privileged resources, thereby undermining system confidentiality, integrity, and availability. The weakness is identified as CWE-416, a failure to safely manage freed memory.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2016, 2019, 2022, and 2025, including both Server Core and non‑Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high‑medium risk level. The EPSS score is below 1%, suggesting a very low probability of exploitation in the wild at present, and the flaw is not listed in the CISA KEV catalog. The attack vector is local, requiring the attacker to have some authorized presence on the target system. The flaw does not appear to allow remote exploitation based on the provided description, but local privilege escalation can still have severe consequences if the attacker gains administrative level access.
OpenCVE Enrichment