Impact
This vulnerability is a kernel‑level use‑after‑free that enables an attacker who can run arbitrary code locally to gain SYSTEM privileges. The flaw is identified as CWE‑416, and given its local nature, any code executing in user mode can potentially trigger the bug, leading to a complete compromise of the host.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 24H2, 25H2, and 26H1, Windows Server 2022, and Windows Server 2025—including Server Core installations—are affected. The updates addressing this issue are listed in the Microsoft Security Update Guide.
Risk and Exploitability
The CVSS score of 7.0 signifies a medium severity impact, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local code execution, after which an attacker can elevate privileges to SYSTEM level, providing full control over the affected machine.
OpenCVE Enrichment