Impact
Use‑after‑free in the Windows kernel permits an attacker with local authorization to gain privileges beyond their user level.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, including Server Core installations. The flaw affects ARM64 builds of Windows 11 24H2 and 25H2 and x64 Windows 11 26H1, along with all builds of Windows Server 2025.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity; however, because the vulnerability requires local attacker authorization, the likelihood of exploitation remains limited to environments where such access already exists. The absence of an EPSS score and the lack of listing in the CISA KEV catalog suggest no widespread exploitation is currently documented. Nonetheless, if exploited, the use‑after‑free can allow an attacker to execute code with elevated privileges, compromising system integrity.
OpenCVE Enrichment