Impact
The flaw is a use‑after‑free bug in Microsoft’s Brokering File System that can be triggered by any authenticated local user. When exploited, the attacker gains higher privileges on the impacted system, enabling the execution of arbitrary code with elevated rights. The weakness is classified as a race condition (CWE‑362) and a use‑after‑free (CWE‑416).
Affected Systems
This vulnerability affects Microsoft Windows 11 build 24H2 (arm64), 25H2 (arm64), and 26H1 (x64), as well as Windows Server 2025, including Server Core installations. All affected images are listed in the Microsoft Security Update Guide for CVE‑2026‑50458.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity for local attackers, whereas the EPSS score of less than 1% indicates that exploitation attempts are presently uncommon. The vulnerability is not present in the CISA KEV catalog. It requires an authorized user to be logged on and to have sufficient rights to initiate the use‑after‑free sequence; no remote exploitation or additional software is necessary.
OpenCVE Enrichment