Impact
The vulnerability is a use‑after‑free flaw in Microsoft XML Core Services that enables an attacker with local authorized access to gain elevated privileges. By freeing a memory object and reusing it, the attacker can execute code with higher privileges than the original user, permitting installation of malware or unauthorized data access. The flaw is categorized as CWE‑416 and is explicitly described as a local privilege escalation without denial‑of‑service or remote exploitation.
Affected Systems
Affected releases include Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2, Microsoft Windows 11 Versions 24H2, 25H2, 26H1, and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, each in both full and Server Core installations, covering 32‑bit x86, 64‑bit x64, and arm64 architectures as indicated by the listed CPEs.
Risk and Exploitability
The CVSS score of 7.0 classifies the flaw as high‑severity local privilege escalation. With an EPSS score below 1 %, the likelihood of active exploitation is currently low, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires local, authorized access to supply crafted XML content to the vulnerable component. If successful, the attacker could run code with administrative rights, creating significant risk in environments where users can edit or execute XML files.
OpenCVE Enrichment