Impact
A use‑after‑free flaw in the Windows DirectX graphics kernel enables an attacker with local authorization to gain elevated privileges on the system. The vulnerability allows the attacker to execute arbitrary code with kernel‑level access, potentially compromising confidentiality, integrity, and availability of the affected machine. The underlying weakness is a memory‑management error that is classified as CWE-416.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025, including Server Core installations, are impacted by this exploit. The vulnerability is present across ARM64 and x64 builds of the listed operating systems.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity for local privilege escalation. The EPSS score of less than 1 % suggests that the likelihood of this vulnerability being exploited in the wild is currently very low, and it is not included in the CISA KEV catalog. The likely attack path requires an authorized user who can run code on the target machine, which is typically an application or driver with elevated privileges. An attacker would trigger the use‑after‑free condition to execute code in kernel mode. While the vulnerability remains unlisted as a known exploited vulnerability, users should treat it as a legitimate security risk due to its potential impact.
OpenCVE Enrichment