Impact
The vulnerability is a use‑after‑free in the Schannel component of Windows, allowing a local authorized attacker to run code with higher privileges. The flaw stems from CWE‑416, which can compromise confidentiality, integrity, or availability of the affected system. An attacker who can execute code locally on the machine may gain administrative privileges, potentially leading to full system compromise.
Affected Systems
Microsoft Windows 11 version 24H2, 25H2, and 26H1, as well as Windows Server 2025—including Server Core installations—are affected by the flaw.
Risk and Exploitability
The CVSS score is 7.8, indicating high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring the attacker to already have authorization on the target system. If exploitation succeeds, an attacker can elevate privileges on the affected machines.
OpenCVE Enrichment