Impact
The vulnerability is a use‑after‑free in Windows NTFS that permits an authorized local attacker to gain elevated privileges, a race‑condition and memory reuse flaw identified as CWE‑362 and CWE‑416. This flaw allows the attacker to execute code or perform actions with higher privileges than the initiating user, potentially compromising system integrity and confidentiality.
Affected Systems
Microsoft Windows 10 Versions 1809, 21H2, and 22H2; Microsoft Windows 11 Versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019, 2022, and 2025, including their Server Core installations. The affected editions span x86, x64, and arm64 architectures as indicated by the CPE list. No other vendors or products are listed as affected by the CNA.
Risk and Exploitability
The CVSS score of 7 reflects a high‑severity local privilege escalation, but the EPSS score of less than 1% indicates that exploitation in the wild is unlikely. The vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread attacks are known. The likely attack vector is a local authenticated user with the ability to manipulate files and trigger the NTFS use‑after‑free, making it a local only scenario that could compromise the entire system once the privilege escalation succeeds.
OpenCVE Enrichment