Impact
The vulnerability is a use‑after‑free condition in the Windows Backup Engine that allows an attacker who already has local system access to execute code with elevated rights beyond those originally granted, leading to privilege escalation. The weakness is classified as CWE‑416.
Affected Systems
The flaw affects Microsoft Windows 10 versions 21H2 and 22H2, and Microsoft Windows 11 versions 24H2, 25H2, and 26H1 on the processor architectures specified in the official CPE entries (x86 for 21H2, x64 for 22H2, arm64 for 24H2 and 25H2, and x64 for 26H1).
Risk and Exploitability
The CVSS score of 7 indicates high severity and the EPSS score of < 1 % reflects a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale attacks. The flaw is a use‑after‑free in the Windows Backup Engine and requires the attacker to already possess local system access to trigger. The affected Windows versions are 10 21H2 (x86), 10 22H2 (x64), 11 24H2 (arm64), 11 25H2 (arm64), and 11 26H1 (x64), as defined by the official CPE entries.
OpenCVE Enrichment