Impact
The vulnerability is a use‑after‑free flaw in the Windows Bind Filter Driver that allows an authorized local user to execute code with elevated system privileges, enabling a local privilege escalation. The CVE description does not specify the exact trigger mechanism; however, the flaw involves the driver’s handling of network binding objects. Based on the description, it is inferred that an attacker must interact with the Bind Filter Driver in some manner to trigger the use‑after‑free, but the precise conditions or malformed data required are not disclosed.
Affected Systems
Affected systems include Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Microsoft Windows Server 2025 (including Server Core installations). These releases rely on the Bind Filter Driver component and are listed by Microsoft as vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local‑privilege capability. The flaw requires local authorization and can be exploited by a legitimate user already present on the system, limiting the attack surface to local accounts. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting that documented exploitation is not currently widespread. Nonetheless, local administrators or service accounts that can interact with the driver pose a risk and should be monitored for anomalous behavior.
OpenCVE Enrichment