Impact
This vulnerability is a use‑after‑free bug in the Windows Media component that permits an attacker with local access to execute arbitrary code with elevated rights. Based on the description, it is inferred that the flaw occurs when a previously freed memory region is reused, allowing the attacker. The weakness is identified as CWE‑416.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The advisory assigns a CVSS score of 7.8, indicating a moderate severity. The EPSS score of 2 % suggests a low probability of exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires local access and can only be leveraged after the attacker has engaged with the Media component on a compromised or user‑controlled machine, so reinforcing least‑privilege principles and keeping the latest Microsoft update mitigates the risk.
OpenCVE Enrichment