Impact
The vulnerability is a use-after-free flaw in the Windows Application Model Core API that can be triggered by an authorized user with local access. Exploitation allows the attacker to execute code with higher privileges than the current account, enabling compromise of system integrity and potentially the entire machine. This type of flaw is identified as CWE-416.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 24H2, 25H2, and 26H1; Microsoft Windows Server 2016, 2019, 2022, and 2025 – both standard and Server Core installations. All affected editions run the Windows Application Model component that contains the vulnerable code.
Risk and Exploitability
The CVSS base score of 7.8 classifies this as a high‑severity, local privilege escalation. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to already have logged on or have some level of local access; from there they could trigger the use‑after‑free and elevate privileges. No public exploit is known, so the risk in the current environment is moderate until the patch is applied.
OpenCVE Enrichment