Impact
A use‑after‑free flaw in the Windows Unified Consent System permits an authorized local user to elevate their privileges, enabling the execution of actions with higher authority on the same machine. The vulnerability is classified as CWE‑416, reflecting an improper deallocation of memory that leads to uncontrolled access.
Affected Systems
Microsoft Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1, Windows Server 2025, and Windows Server 2025 (Server Core installation).
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and the supplied data does not mention a publicly available exploit. The flaw requires an attacker to already have local access to the system; based on the description, the likely attack vector involves local interaction with the Unified Consent System. Although the EPSS indicates a low likelihood of exploitation today, the potential impact of a successful privilege escalation remains substantial.
OpenCVE Enrichment