Impact
A use‑after‑free flaw in the Windows Clipboard Server allows an attacker who is already authenticated to a system to execute code with elevated privileges. The bug arises from a race condition that leaves a dangling pointer that an attacker can exploit to run arbitrary code in the context of the Clipboard Server, which runs as a system service. When successful, the attacker can gain local administrative rights, potentially installing malware, modifying system settings, or moving laterally within the environment.
Affected Systems
Affected products include Microsoft Windows 10 versions 1809, 21H2, 22H2; Microsoft Windows 11 versions 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2019 (including Server Core), 2022, and 2025 (including Server Core). The Clipboard Server is a core component in all of these operating systems.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating a high severity level, while the EPSS score is less than 1%, suggesting that real‑world exploitation is currently unlikely. It is not listed in the CISA KEV catalog. The flaw requires a local, authorized attacker with an active session; thus the attack vector is primarily insider or local. Nonetheless, given the potential to achieve administrative privileges, the threat remains significant and warrants rapid patching.
OpenCVE Enrichment