Impact
The vulnerability is a use‑after‑free flaw in Windows kernel‑mode drivers that allows an authorized local user to gain elevated privileges by accessing memory that has already been freed. This misuse of memory can lead to arbitrary kernel‑level code. The improper freeing of resources after use.
Affected Systems
Affected systems include Microsoft Windows 11 24H2 and 25H2 ARM64 builds, Windows 11 26H1 x64 build, and Windows Server 2025 in both standard and Server Core installations. All current releases of these platforms remain vulnerable until Microsoft releases an official update.
Risk and Exploitability
The CVSS score of 7 marks the issue as high severity. With an EPSS score of less than 1 % and no listing in the CISA KEV catalog, widespread exploitation is considered unlikely but feasible for a local attacker. The likely attack vector is a trusted user who can load kernel‑mode drivers, which is then able to trigger the use‑after‑free and exploit it; based on the description, it is inferred that an attacker would need administrative or driver‑install privileges to carry out the exploit.
OpenCVE Enrichment