Impact
The vulnerability is a use‑after‑free condition in the Windows Sensor Data Service that permits an authorized local user to elevate privileges. If exploited, a non‑privileged account can acquire higher authority, potentially compromising credential storage, system settings, and other protected resources, thereby affecting confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected by Microsoft systems, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1), Windows Server 2016 and Server Core, Windows Server 2019 and Server Core, Windows Server 2022, and Windows Server 2025 (including Server Core). These are the versions listed by the CNA as vulnerable.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity for local privilege escalation. The EPSS score of less than 1% suggests that exploitation is considered rare at present and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector requires an authorized attacker who already has some level of local access; no public remote exploitation methods are documented.
OpenCVE Enrichment