Impact
The vulnerability is a use‑after‑free condition in the Windows Logon Manager (Winlogon) that allows a local authorized attacker to gain elevated privileges on the system. The flaw results in the execution of code in a higher privilege context, potentially granting the attacker full administrative rights. This weakness is classified as CWE‑416, which indicates memory corruption due to the improper handling of freed memory.
Affected Systems
The flaw affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server releases from 2012 through 2025. All architecture variants listed in the CPE data are impacted.
Risk and Exploitability
The CVSS score of 7.0 reflects a medium to high severity, and the vulnerability is not currently listed in the CISA KEV catalog. While the EPSS score is not available, the local authorization requirement suggests the threat is limited to software execution by an attacker who already has access to the machine. The attack path involves a local user triggering the use‑after‑free within Winlogon, thereby enabling privilege escalation. If mitigated, the risk of unauthorized privilege elevation on the affected platforms is eliminated.
OpenCVE Enrichment