Impact
A use‑after‑free flaw in Windows Storage can be triggered by an authorized local user to gain elevated privileges. The vulnerability arises from a race condition and an improper release of memory; the race condition is inferred from the use‑after‑free nature but is not explicitly stated in the source, leading to execution of code with higher privileges once the flaw is exploited. Attackers can leverage the elevated rights to perform any action that the higher privilege level allows, such as modifying system settings, installing software, or accessing protected data.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2, and Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019, 2022, and 2025 (both standard and Server Core installations).
Risk and Exploitability
The CVSS score of 7 indicates a high severity with potential for local privilege escalation. The EPSS score of less than 1% suggests a low exploitation probability at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to be authenticated on the affected system to exploit the flaw.
OpenCVE Enrichment