Impact
The vulnerability is a use‑after‑free flaw in the Windows kernel. An attacker who is already authenticated on the target machine can exploit the bug to gain higher privileges, potentially allowing full control of the system. The flaw results in an elevation of privilege attack, as captured by CWE‑416 (Use After Free).
Affected Systems
The flaw affects Microsoft Windows 11 releases 23H2, 24H2, 25H2 and 26H1, as well as Microsoft Windows Server 2025, including Server Core installations. Versions with the ARM64 and x64 architectures are impacted, as referenced by the CPE entries for those platforms.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity. The EPSS score is 1%, but the catalog entry is not listed in KEV, which suggests no publicly known exploitation at this time. The attack vector is local: a legitimate user must already be logged in to trigger the kernel exploit. While the use‑after‑free can be challenging to exploit, the available patch mitigates the risk.
OpenCVE Enrichment