Impact
The vulnerability is a use‑after‑free flaw in the Windows Media component that lets an authorized local user gain higher privileges on the affected Windows system. The impact is the elevation of privileges, which could enable the user to perform actions normally restricted to administrators.
Affected Systems
Affected Windows operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2016, 2019, 2022, and 2025, with both standard installations and Server Core variants.
Risk and Exploitability
The CVSS score of 7 indicates high severity, and the EPSS score of less than 1% reflects a very low probability of exploitation in the real world. The vulnerability is not listed in CISA’s KEV catalog. It is exploitable only by an authorized local user who can trigger the Windows Media component, making the attack vector local and contingent on the user’s ability to run media files.
OpenCVE Enrichment