Impact
The flaw is a use‑after‑free in Windows Installer that permits an authorized attacker to elevate privileges locally. The vulnerability arises when a previously freed memory reference is reused, enabling the attacker to execute code with escalated privileges. The impact is local privilege escalation, potentially allowing the attacker to run privileged commands or install malicious software on the affected system.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1) are affected. All listed processor architectures (x86, x64, arm64) from the CPE data are susceptible. The vulnerability also impacts Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score is 7, indicating a high‑severity local privilege escalation flaw. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The vulnerability requires an authorized user who can invoke Windows Installer; therefore, local access is necessary for exploitation. No public exploit details are provided in the CVE data.
OpenCVE Enrichment