Impact
This vulnerability is a use‑after‑free flaw in the Windows USB Print Driver that enables an authorized attacker with local code execution to elevate privileges. By accessing freed memory references, the attacker can execute privileged operations on the affected system.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 (including Server Core installations) are affected. The flaw impacts arm64 builds of Windows 11 24H2 and 25H2, and x64 builds of Windows 11 26H1, with all builds of Windows Server 2025.
Risk and Exploitability
The CVSS score of 7 indicates high severity for local privilege escalation, while the EPSS score of less than 1% shows that recent exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed public exploitation. Based on the description, the likely attack vector is an authorized user capable of running code locally, such as through a malicious USB print driver.
OpenCVE Enrichment