Impact
Microsoft Brokering File System contains a double free bug that allows a local attacker with existing user privileges to elevate privileges. The race condition that triggers the double free can lead to kernel memory corruption (inferred from the nature of double free and race condition), allowing the attacker to gain system‑level rights, modify critical system files, or install malicious software.
Affected Systems
Microsoft Windows 11 Version 24H2 (arm64), Microsoft Windows 11 Version 25H2 (arm64), Microsoft Windows 11 Version 26H1 (x64), Microsoft Windows Server 2025 including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity if the vulnerability is exploited. An EPSS score of less than 1% suggests a very low probability of real‑world exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, reducing immediate threat posture concerns. Exploitation requires local system interaction; the attacker must already have local access to trigger the race condition and double free.
OpenCVE Enrichment