Impact
Use‑after‑free occurs in the Windows VMSwitch component when a memory object is freed while still referenced, allowing an attacker who can communicate with the device to execute privileged operations normally reserved for administrators. This flaw can give the attacker full control over the host, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions from 2012 through 2025, including Server Core installations, are affected across x86, x64, and ARM64 architectures.
Risk and Exploitability
The CVSS score of 9.9 marks this vulnerability as critical, but the EPSS score below 1% indicates a very low likelihood of exploitation at this time. It is not listed in the CISA KEV catalog. The attack requires an authenticated or network‑authorized actor able to send crafted packets to the VMSwitch service; once triggered, the use‑after‑free enables execution of code with elevated privileges.
OpenCVE Enrichment