Impact
An authorized local attacker can exploit a use‑after‑free flaw in the Windows Runtime to gain higher privileges. The vulnerability allows the attacker to execute code with elevated rights, potentially enabling further compromise or persistent foothold. The weakness is classified as CWE‑416 and presents a vulnerability for local privilege escalation.
Affected Systems
Microsoft Windows 11 24H2, 25H2 and 26H1, as well as Microsoft Windows Server 2025 (including Server Core installations). ARM64 builds of Windows 11 24H2 and 25H2, and x64 builds of Windows 11 26H1, are affected. The same vulnerability also applies to all Windows Server 2025 deployments.
Risk and Exploitability
The CVSS score of 8.8 reflects a high severity rating, while the EPSS score of less than 1 % indicates a low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV list. Because the flaw requires a local authorized attacker, the attack vector is inferred to be local; the attacker must have access to the machine to trigger the use‑after‑free and gain elevated privileges.
OpenCVE Enrichment