Impact
The vulnerability is a use‑after‑free flaw in the Microsoft Brokering File System that allows a local attacker with authorized access to elevate their privileges. This weakness is classified as CWE‑362 (Race Condition) and CWE‑416 (Use after Free).
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (including Server Core installations) are affected. The flaw targets the file‑system component that brokers operations across processes. The Windows 11 builds apply to arm64 architectures for 24H2 and 25H2 and the x64 architecture for 26H1, while the Windows Server 2025 builds are generic.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high‑moderate severity local privilege escalation. The EPSS score of less than 1% suggests a low likelihood of public exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, implying no known active exploits. Attackers must be authenticated and authorized locally to exploit the race condition and gain elevated privileges, which could enable system‑wide control. Despite the low exploitation probability, rapid patching is advised due to the potentially severe local privilege escalation.
OpenCVE Enrichment