Impact
The vulnerability is a use‑after‑free flaw in the Windows Runtime that, when triggered by an authorized user, permits the execution of code with elevated privileges. It involves a data race condition (CWE-362) and a memory safety issue (CWE-416). An attacker who can initiate the exploit locally could gain higher privileges, potentially affecting the entire system.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; Microsoft Windows Server 2019 and Server Core; Microsoft Windows Server 2025 and Server Core.
Risk and Exploitability
The CVSS score of 7.8 reflects a high impact of the flaw, while the EPSS score of less than 1% suggests an unlikely exploitation rate at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an authenticated attacker to trigger the use‑after‑free and elevate privileges.
OpenCVE Enrichment