Impact
An authorized attacker can exploit a use‑after‑free flaw in Windows DirectX to gain elevated privileges locally. The weakness is classified as class 416, indicating a memory safety issue that allows a process to access freed memory after it has been freed.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score is 7, with an EPSS of less than 1 %, indicating limited exploitation potential currently. The vulnerability remains outside of CISA’s KEV catalog. Exploitation requires a local, authorized user, and the likely attack vector is through untrusted DirectX content triggering a use‑after‑free in the graphics kernel, a conclusion inferred from the description. If successfully exploited, the attacker can elevate their privileges, potentially compromising the entire system.
OpenCVE Enrichment