Impact
The vulnerability is a use‑after‑free flaw in Application Information Services that allows a local authorized attacker to elevate privileges on the affected system. As a result, the attacker could gain full control, read or modify system files, and potentially disrupt services, compromising the confidentiality, integrity, and availability of the host.
Affected Systems
The weakness affects Microsoft Windows 11 versions 24H2, 25H2 and 26H1, as well as Windows Server 2025 and its Server Core installation. The Windows 11 builds 24H2 and 25H2 run on arm64 architectures, while 26H1 runs on x64.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, yet the EPSS score of less than 1% implies a low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. An attack requires local authorized access, likely from a user who can trigger the use‑after‑free, and would result in elevated privileges equivalent to system or administrative rights.
OpenCVE Enrichment