Impact
The vulnerability is a double free defect (CWE‑415) in the Windows Kerberos implementation that allows an authenticated local user to raise their own privileges. Because the same memory block can be freed twice, the flaw can be leveraged by a local attacker to gain administrative or similarly high authorizations on the affected system. No disclosure of code execution or remote compromise is present in the available data. Based on the description, it is inferred that this vulnerability does not enable remote code execution or compromise.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2 and 26H1, as well as Microsoft Windows Server 2025, including Server Core installations, are affected.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity, and the EPSS score of 1% shows a low exploitation probability. The flaw is usable only by users who already have local access to the system, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed. (Based on the description, it is inferred that the attack surface is limited to authenticated local users.) Consequently, the risk is significant for systems that host local accounts with administrative privileges, but the attack surface is limited to authenticated users on the affected machines. Prompt remediation is therefore recommended.
OpenCVE Enrichment