Impact
Use after free in Windows Netlogon allows an authorized attacker who can reach the affected system to elevate privileges over a network. The flaw can enable the attacker to gain higher privileges, potentially achieving full administrative control, and is identified as CWE‑416, a memory safety weakness that can subvert privileged execution paths.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.5 reflects a medium‑to‑high severity, while the EPSS score of less than 1 % and absence from CISA’s KEV catalog suggest a low current exploitation probability. The likely attack vector is network‑based: an attacker with legitimate or compromised network access can communicate with Netlogon services on domain controllers to trigger the use‑after‑free and raise privileges. The flaw is constrained to hosts that accept such network traffic, indicating insider or compromised‑account exploitation is most relevant.
OpenCVE Enrichment