Impact
A use‑after‑free error in the Windows Graphics Kernel allows an attacker with local, authorized access to elevate the privileges of processes running on the affected systems. The vulnerability is a classic memory corruption flaw (CWE‑416) that can enable privileged execution of code within the kernel space, undermining the isolation between user and system components. While the description does not explicitly state arbitrary code execution, the elevation of privileges can be leveraged to install malware, gain administrative control, or compromise critical system functions.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and the Windows Server family—including 2016, 2019, 2022, and 2025, both standard and Server Core installations—are affected by this kernel flaw.
Risk and Exploitability
The CVSS base score of 7 indicates a high severity within the moderate‑to‑high range. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. It is inferred that the attack vector is local, requiring an attacker to have some level of authorized access to the system, such as a logged‑in user or a compromised application with local privileges. The use‑after‑free flaw in kernel mode can thus be abused to gain elevated rights that affect the entire system.
OpenCVE Enrichment