Impact
A use‑after‑free flaw in the Windows Win32k kernel allows an authorized local user to gain elevated privileges. With elevated privileges the attacker can execute arbitrary code, install malware, exfiltrate data, or disrupt services, thereby compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012 (including Core), 2012 R2, 2016, 2019, 2022, and 2025 (including Core). All supported x86, x64, and ARM64 architectures are affected depending on the specific OS release.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of 2% signals a low to moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploitation to date. Attackers must already have local access and authorization; any local user with suitable privileges can potentially exploit the flaw, creating a foothold for lateral movement within the network.
OpenCVE Enrichment