Impact
The vulnerability is a use‑after‑free flaw in the DirectX graphics kernel that permits an authorized local user to gain kernel‑level privileges. Falling under CWE‑416, the flaw enables the execution of arbitrary code with elevated rights, thereby potentially compromising the integrity and confidentiality of the affected system.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2016, 2019, 2022, and 2025, both standard and Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity local impact, while the EPSS score of less than 1% suggests that exploitation is not widely observed at this time and the flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker requires a legitimate local user with the ability to trigger the use‑after‑free condition in DirectX components, implying a local and non‑remote attack vector.
OpenCVE Enrichment