Impact
The vulnerability is a use‑after‑free condition within the Windows Bind Filter Driver that allows an attacker with local, authorized access to gain higher privileges on the system. It is rooted in race‑condition and memory reclamation weaknesses identified as CWE‑362 and CWE‑416. An attacker who can exploit this defect may acquire administrative or system-level rights, compromising confidentiality, integrity, and availability of the affected machine.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (including the Server Core installation), are affected. The driver is present on arm64 builds for the 24H2 and 25H2 releases and on x64 for 26H1; the server edition is affected but its architecture has not been disclosed.
Risk and Exploitability
The CVSS score of 7 indicates a medium severity issue, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. It requires an authorized local attacker, meaning the attacker must already have some level of access to the target machine. The use‑after‑free flaw can be triggered by manipulating the Bind Filter Driver’s state, potentially allowing the attacker to execute privileged code. The lack of a public exploit and absence from KEV reduce the likelihood of widespread exploitation, but the local nature of the attack vector makes it a serious risk in environments where privileged users or compromised local accounts exist.
OpenCVE Enrichment