Impact
The vulnerability is an use‑after‑free flaw in the Windows DWM Core Library that executes in kernel mode. When successfully triggered, it lets a user‑level attacker gain system rights, effectively allowing arbitrary code execution with privileged access. The issue arises from improper memory handling (CWE‑416).
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019 (including Server Core), Microsoft Windows Server 2022, and Microsoft Windows Server 2025 (including Server Core) are all affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, while an EPSS score of 2 % denotes a relatively low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires local authentication, meaning an attacker must already have some level of access to the target machine, and the use‑after‑free must be triggered within the kernel to achieve privilege escalation.
OpenCVE Enrichment