Impact
A use‑after‑free flaw in Windows Secure Kernel Mode lets a local, authorized attacker raise privileges to Administrator or SYSTEM. The vulnerability is a classic memory corruption error that bypasses normal access controls, enabling the attacker to load malicious code with kernel privileges. Once escalated, the attacker can manipulate system settings, install software, or read and modify protected data, potentially compromising the entire machine.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (both regular and Server Core installations). The affected architectures include arm64 for the 24H2 and 26H1 releases and x64 for the 25H2 release.
Risk and Exploitability
The CVSS score of 7.0 indicates a severe impact. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. However, the attack requires local access and an authorized user context, which means any user with legitimate access could potentially leverage the flaw. The combination of high severity and low exploitation probability places the risk in the moderate category, but organizations should not delay remediation.
OpenCVE Enrichment