Impact
The vulnerability is a use‑after‑free flaw in the Windows Client‑Side Caching (CSC) Service that permits an authorized attacker running locally to elevate privileges. By triggering the improperly freed memory region, the attacker can execute arbitrary code or modify system state with higher‑privilege permissions. The weakness is classified as a memory‑management error (CWE‑416).
Affected Systems
Microsoft Windows 10 (version 1607, 1809, 21 H2, 22 H2), Windows 11 (24 H2, 25 H2, 26 H1), Windows Server 2012, Server 2012 R2, 2016, 2019, 2022, 2025, and all corresponding Server Core installations are affected.
Risk and Exploitability
The CVSS score is 7, indicating high severity. EPSS is less than 1 %, implying a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploit requires local execution; the attacker must already be authenticated on the machine, possess the ability to interact with the CSC service, and then trigger the use‑after‑free to gain elevated local privileges.
OpenCVE Enrichment