Impact
Windows Media contains a use‑after‑free flaw that, when triggered by an authorized local user, can elevate the attacker’s privileges on the target machine. The vulnerability is classed as CWE‑416 (Use After Free) and CWE‑362 (Race Condition), indicating that memory corruption can occur during the normal operation of the component.
Affected Systems
Microsoft Windows 11 version 24H2, 25H2, and 26H1 are affected. Builds 24H2 and 25H2 target arm64 devices, while 26H1 applies to x64 architecture.
Risk and Exploitability
The CVSS score of 7.8 denotes high severity, and the EPSS score of less than 1 % suggests that widespread exploitation is presently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a local user with an authorized account who can interact with the Windows Media component; only such users can exploit the flaw to gain elevated privileges.
OpenCVE Enrichment