Impact
A use–after–free flaw in Windows Management Services lets a locally authorized attacker exploit a freed memory pointer. By triggering the flaw, the attacker can gain elevated privileges, effectively turning a standard user into an administrator and allowing full control of the system. The weakness is classified as CWE‑416 and is typical of memory corruption bugs that can lead to arbitrary code execution when locally privileged code triggers the flaw.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025, including Server Core installations, are affected. These builds are listed explicitly in the CNA product list and the advisory from Microsoft.
Risk and Exploitability
The CVSS v3.1 score of 7.0 indicates medium‑to‑high severity. The EPSS score of less than 1% suggests that exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local and requires an authorized user or process to trigger the flaw, which means that restricting local administrative rights can reduce risk. Overall, the exposure is moderate, but remediation is strongly recommended to prevent a potential privilege escalation scenario.
OpenCVE Enrichment