Impact
The vulnerability is a use‑after‑free flaw in Windows Kerberos that is exploitable by an authenticated user with local access. By triggering this memory corruption, a malicious actor can raise the privileges of their own account or any account that the victim has permission to elevate, thereby compromising confidentiality, integrity, and availability of the affected system. The weakness is identified as CWE‑416.
Affected Systems
Affected systems are Microsoft Windows operating systems and servers including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (all core and non‑core builds).
Risk and Exploitability
The CVSS score of 7 indicates significant risk; however, the EPSS score is not available, so the precise probability of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog. It requires an authorized local user to initiate the attack, making it a local privilege escalation vector rather than a remote exploit. The exploitation path involves sending crafted Kerberos messages that exploit the use‑after‑free condition in the Kerberos subsystem, allowing the attacker to override security descriptors or elevate privileges with the session’s token.
OpenCVE Enrichment