Impact
This vulnerability is a use‑after‑free flaw in the Windows kernel (CWE-416) that allows an authorized local attacker to increase their privileges. The flaw can be exploited only by users who already have access to the affected system, but it enables them to gain higher privileges and take full control of that machine, potentially compromising all data and processes on it.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; Windows Server editions 2016, 2019, 2022, and 2025, including Server Core installations for 2016, 2019, and 2025.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity overall. The EPSS score is below 1%, suggesting that attacks are currently rare but remain possible. The vulnerability is not listed in CISA KEV, meaning no known widespread exploitation. The attack vector is local; an attacker who can run code on the target machine can trigger the use‑after‑free flaw in the Windows kernel to elevate privileges, thereby gaining full control of the system.
OpenCVE Enrichment