Impact
This vulnerability is a use‑after‑free flaw in the Windows Virtual Hard Disk (VHD) miniport driver. An attacker who already has local access to the system can trigger the vulnerability to cause the driver to execute code in the context of a higher‑privileged process, thereby gaining elevated privileges. The weakness is classified as CWE‑416 and can lead to local privilege escalation, compromising confidentiality, integrity, and availability of the affected systems.
Affected Systems
Affected Microsoft products include Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and Windows Server (2019, 2022, 2025) across both standard and core installations.
Risk and Exploitability
The CVSS base score is 7.8, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local, authorized user to manipulate the VHD driver, which limits the attack surface relative to remote attacks but still poses a significant risk in environments where privileged processes are misused. Proper patching and configuration can mitigate this threat.
OpenCVE Enrichment