Impact
The vulnerability is a use‑after‑free within the Windows Hyper‑V component, classified as CWE‑416. An attacker who is already authorized on the host and can interact with the Hyper‑V feature can use the flaw to elevate privileges locally. The flaw does not allow remote code execution or network‑based exploitation; it requires local access to the host.
Affected Systems
Affected operating systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019 (including Server Core installation), Windows Server 2022, and Windows Server 2025 (including Server Core installation).
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity level, while the EPSS score of less than 1% denotes a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The use‑after‑free flaw can be triggered by a local, authorized user who has the ability to use Hyper‑V, and it results in privilege escalation to system-level tokens on the host. While the risk of exploitation remains low, the impact of successful exploitation is significant, warranting prompt remediation.
OpenCVE Enrichment