Impact
A use‑after‑free flaw exists within the Windows Graphics Kernel, permitting an attacker who has local user credentials to obtain higher privileges. The vulnerability resides in the handling of graphical objects, where an attacker may trigger a freed memory reference to execute privileged code. Once exploited, the attacker can elevate a local account to SYSTEM level, gaining full control over the affected machine. The weakness is characterized by CWE-416, a use‑after‑free defect.
Affected Systems
The flaw affects several Microsoft operating system releases, including Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; as well as Windows Server 2019, Server 2022, and Server 2025, including both full and Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high severity condition; however, the EPSS score is reported as less than 1 percent, suggesting a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authorized local user who can intentionally invoke the flaw through a crafted graphics operation. Without such a local foothold, the attack surface remains limited to users with sufficient privileges to execute arbitrary code on the host.
OpenCVE Enrichment