Impact
A use‑after‑free flaw in the Windows Virtual Hard Disk Miniport Driver permits an attacker with local, authenticated access to elevate privileges. The bug lets the driver free an object and later reference it, potentially enabling code execution with elevated rights. As a result, compromised users can gain administrative privileges on the affected machine, compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects multiple Microsoft operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1 and 23H2 again, as well as Windows Server 2016, 2019, 2022, and 2025, both full and Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a moderate‑to‑high severity risk. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the local attack vector requires the attacker to have logged‑on credentials, but once authenticated, privilege escalation can occur. There is no publicly available exploit, so the risk is primarily theoretical until malicious actors develop an exploit. Organizations with users that have local administrator rights are at higher risk.
OpenCVE Enrichment