Impact
The vulnerability is a use‑after‑free in the Windows kernel that allows an authorized local attacker to execute arbitrary code with kernel privileges, resulting in full local privilege escalation and the ability to gain SYSTEM level access.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2012, 2012 (Server Core), 2012 R2, 2012 R2 (Server Core), 2016, 2016 (Server Core), 2019, 2019 (Server Core), 2022, 2025, and 2025 (Server Core); all affected architectures (x86, x64, arm64).
Risk and Exploitability
The CVSS score of 7 indicates high severity, while the EPSS score of <1% suggests that exploitation in the wild is unlikely; the vulnerability is not listed in CISA’s KEV catalog. The flaw requires authorized local access and involves triggering a crafted input that causes kernel code to execute freed memory, so remote attackers cannot use this flaw without prior local compromise.
OpenCVE Enrichment