Impact
Use‑after‑free in a Windows kernel‑mode driver allows an authorized local attacker to gain elevated privileges. After the driver is unloaded and memory freed, the attacker can invoke the dangling reference to hijack control flow and execute code with higher permissions.
Affected Systems
Affected systems include Microsoft Windows 11 24H2 and 25H2 on arm64 architectures, Microsoft Windows 11 26H1 on x64 architecture, and Microsoft Windows Server 2025 and the Server Core installation of Windows Server 2025.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating a High severity. The EPSS score is less than 1%, suggesting low exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires a local administrator or privileged account; an authenticated user could invoke the kernel driver in a way that triggers the use‑after‑free, thereby elevating privileges. Because the attack vector is local and requires authorization, widespread exploitation is unlikely, but the impact on a compromised device would be substantial.
OpenCVE Enrichment