Impact
The flaw is a use‑after‑free in the Windows kernel that is triggered by manipulating Win32k objects. It is classified as CWE‑416. If an attacker who is already authenticated on the machine can exploit this race condition, they can elevate their privileges to administrator or SYSTEM, thereby gaining the ability to execute arbitrary code, modify protected system files, or obtain sensitive information.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1 and Windows Server 2025, including Server Core installations, are affected. The CNA lists both ARM64 and x86‑64 architectures for the Windows 11 releases and the server build, indicating that the vulnerability is present across the available hardware platforms.
Risk and Exploitability
The CVSS score of 8.8 signals a high‑severity risk, yet the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not part of the CISA KEV catalog. The attack likely requires a local user who can run code, such as a standard or administrator account, because the use‑after‑free is triggered from a user‑mode context. With successfully elevated privileges, an attacker could maintain persistent access or pivot to higher privileges within the system.
OpenCVE Enrichment