Impact
This vulnerability is a use‑after‑free flaw in the Quality Windows Audio/Video Experience (QWAVE) service. An authorized local attacker can trigger the flaw by influencing the service to reference memory that has already been freed. This can result in the attacker gaining elevated local privileges, allowing execution of arbitrary code with higher rights. The weakness is a classic use‑after‑free, identified as CWE‑416. The impact is a local privilege escalation that can lead to system compromise.
Affected Systems
Affected systems are Microsoft Windows 10, Windows 11, and Windows Server platforms. Windows 10 versions 1607, 1809, 21H2, and 22H2 are affected. Windows 11 releases 24H2, 25H2, and 26H1 are impacted. Windows Server variants - 2012, 2012 R2, 2016, 2019, 2022, and 2025 - across both core and full installations are also vulnerable.
Risk and Exploitability
The CVSS score of 7.0 classifies the flaw as a high severity local privilege escalation. The EPSS score indicates an exploitation is currently uncommon, and it is not listed in the CISA KEV catalog. The likely attack vector is a local, authorized user who can call the QWAVE service; the flaw requires the presence of the service and appropriate privileges to influence its execution. Given the high score and low exploitation probability, organizations should prioritize applying the published patch to eliminate the vulnerability.
OpenCVE Enrichment