Impact
Use after free in Windows Modern Device Management (MDM) enables an authorized local attacker to elevate privileges. The flaw permits execution of arbitrary code with increased rights by exploiting freed memory, representing a classic use‑after‑free bug (CWE‑416) that can lead to full system compromise if the attacker gains administrative access. The likely attack vector is a local user with authorized MDM privileges, as the exploit requires initiating specific MDM operations.
Affected Systems
Affected Microsoft products include Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, 26H1; and Windows Server 2016, 2019, 2022, and 2025, including their Server Core installations. These versions run the vulnerable MDM component that the exploit targets.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity while the EPSS score of less than 1 % points to a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog, signifying no known public exploitation. The flaw requires a local attacker with MDM privileges to invoke the vulnerable operation, potentially gaining administrative rights. Due to the local nature, patching and strict access control greatly reduce the risk.
OpenCVE Enrichment