Impact
The vulnerability is a use-after-free condition in the Windows Graphics Kernel that can be triggered by a privileged local process that loads or interacts with a DirectX driver. Based on the description, it is inferred that an attacker would trigger the flaw by loading or interacting with a DirectX driver through a local process. Exploiting the premature deallocation allows the attacker to write arbitrary data to a kernel memory region, leading to elevated privileges and enabling execution of malicious code at the highest level on the host.
Affected Systems
Affected releases include Windows 10 version 1809, 21H2, and 22H2, Windows 11 version 24H2, 25H2, and 26H1, and Windows Server releases 2019, 2022, and 2025, both in normal and Server Core installations. The CVE impacts x86, x64, and ARM64 builds as specified in the CPE listings.
Risk and Exploitability
The CVSS score of 7.8 characterizes the flaw as a moderate-to-high severity vulnerability, while the EPSS score of <1% (approximately 0.00311) indicates a very low likelihood of exploitation in the wild. The vulnerability is not tracked in CISA’s KEV catalog. Exploitation requires local user privileges sufficient to load DirectX drivers; thus an attacker with such access can elevate to system or administrator level, granting unrestricted control over the affected machine.
OpenCVE Enrichment