Impact
An authorized local attacker can exploit a use‑after‑free bug in the Desktop Window Manager (DWM) to elevate privileges. The vulnerability is a memory safety error classified as CWE‑416. The flaw may allow a user who can run code within the victim’s session to obtain higher privileges on the affected machine.
Affected Systems
Microsoft Windows 11, 26H1, 64‑bit build. This is the only product listed as affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity that local privilege escalation is possible. The EPSS score is below 1 % so the chance of spontaneous exploitation is low, and the vulnerability is not listed in CISA KEV. The attack vector requires an authorized attacker with local access, which means it cannot be exploited remotely. However, for environments where local users have extensive privileges or where workstations are not properly fenced, the risk is non‑negligible.
OpenCVE Enrichment