Impact
This vulnerability is a use‑after‑free flaw in the Windows Win32K graphics subsystem. An authorized local attacker can trigger the bug to gain higher privileges on the affected systems. Classified as CWE‑416, the weakness manifests when memory is accessed after being freed, which can lead to unauthorized execution of code or manipulation of system resources. The consequence is that a local user could elevate privileges, potentially achieving administrative rights or compromising system integrity.
Affected Systems
Microsoft Windows 10 releases 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; Windows Server 2019 (both full and Server Core installations); Windows Server 2022; Windows Server 2025 (including Server Core). Affected architectures include x86, x64, and arm64, depending on the specific release.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate‑to‑high severity for local privilege escalation. The EPSS score of 2% reflects a low but non‑negligible probability that this vulnerability will be exploited. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated local user with the ability to run code; the attack vector is strictly local. A maliciously crafted application or content executed during a user session can trigger the use‑after‑free in Win32K, but no remote exploitation path is documented.
OpenCVE Enrichment