Impact
The vulnerability is a use‑after‑free flaw in the Windows Win32K kernel subsystem. Attackers who can execute code with local privileges can trigger the flaw to corrupt kernel memory and gain higher privileges. The flaw is identified as CWE‑416. An attacker who succeeds can elevate to system or administrator level, enabling full control over the affected machine.
Affected Systems
Affected operating systems include all supported releases of Windows 10 from version 1607 to 22H2, Windows 11 from version 24H2 onward, and Windows Server editions from 2016 through 2025, including Server Core installations. The vulnerability exists on x86, x64, and arm64 architectures as applicable.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity vulnerability with local privilege escalation potential. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires a local attacker with a privileged context capable of interacting with the Win32K subsystem; therefore the attack vector is local and requires the attacker to have some authorized user access.
OpenCVE Enrichment