Impact
The vulnerability is a use‑after‑free condition in the Windows Content Delivery Manager. An attacker who is already authorized on the system can trigger the flaw and gain elevated local privileges. The weakness corresponds to a race condition and memory safety error, allowing the attacker to alter program flow and perform actions normally restricted to higher privilege accounts.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019 (including Server Core); and Microsoft Windows Server 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity with potential for full local privilege escalation. However, the EPSS score is below 1 %, implying a very low probability of observed exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local attacker with sufficient authorization who can exploit the use‑after‑free in the Content Delivery Manager to elevate privileges.
OpenCVE Enrichment