Impact
The vulnerability is a double free in the Windows Network Connection Broker that allows any authorized local user to temporarily deallocate an already freed memory block, leading to a flaw that can be exploited to elevate privileges on the same machine. Because the flaw is a memory management issue, an attacker could manipulate the system to run arbitrary code with higher privileges, compromising confidentiality, integrity, and availability.
Affected Systems
Affected systems include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server from 2012 to 2025, including Server Core installations. These appear in the Microsoft catalogue under the listed CPE identifiers, covering both x86 and x64 architectures as well as ARM64 for recent Windows 11 releases.
Risk and Exploitability
The CVSS score of 7 indicates high severity, but the EPSS score of less than 1% shows a very low current exploit probability, and the vulnerability is not cataloged in the CISA KEV. The attack vector is local, requiring the attacker to be on the same system or to have local account privileges; however, because it can raise the user's privileges up to those of the system, the potential impact is substantial.
OpenCVE Enrichment