Impact
The issue is a use‑after‑free flaw within the Windows internal system user profile handler. When triggered by a locally authenticated attacker who can execute code in a legitimate user context, the flaw can alter the behavior of the operating system to grant higher privileges, potentially reaching a privileged or system account. The vulnerability, classified as CWE‑416, enables local privilege escalation without any need for network exploitation.
Affected Systems
Microsoft Windows 10 21H2 and 22H2, Windows 11 24H2, 25H2, and 26H1, and Windows Server 2025—including the Server Core installation—are affected. The listed builds correspond to the specified CPE identifiers and include both x86 and x64 architectures where applicable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests that exploitation in the wild is improbable. The vulnerability is not present in the CISA KEV catalogue. Exploitability requires local access and code execution within a legitimate user session; no remote exploitation method is documented, making this a local privilege escalation scenario.
OpenCVE Enrichment