Impact
The vulnerability is a use‑after‑free condition that can be triggered by an authorized local user, potentially allowing them to execute code with elevated privileges, thereby enabling full system compromise. This weakness is classified as CWE‑416 and results in the loss of integrity and confidentiality for the compromised system.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server (2016, 2019, 2022, 2025, including Server Core installations) are impacted by this flaw.
Risk and Exploitability
The CVSS score of 7.8 reflects a moderate to high severity. No EPSS value is available, making the likelihood of exploitation uncertain, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an authenticated user to trigger the use‑after‑free and achieve privilege escalation.
OpenCVE Enrichment