Impact
A use‑after‑free flaw (CWE‑416) in the Windows Runtime permits an authorized local user to execute code with elevated privileges. The vulnerability can be triggered by a local attacker who has sufficient access to invoke the defective API. After the use‑after‑free, the attacker gains higher privileges than initially granted.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including Server Core installations. The defect affects the runtime components on x86, x64, and arm64 architectures where applicable.
Risk and Exploitability
EPSS indicates a very low likelihood of exploitation in the wild, while the CVSS score of 7 classifies the vulnerability as high severity. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly reported exploitation. Local execution is required; an authenticated user must trigger the use‑after‑free, after which the attacker gains local privileges. The impact of the privilege escalation depends on the scope of the attacked system and the privileges of the compromised user.
OpenCVE Enrichment