Impact
The vulnerability is a use‑after‑free flaw in the Windows kernel that allows an attacker with local access to elevate privileges. Exploitation can enable the attacker to execute code with kernel‑level rights, potentially compromising system integrity and allowing installation of malicious software. This issue is categorized under CWE‑416 (Use‑After‑Free) and CWE‑362 (Concurrent Modification of Shared Resource).
Affected Systems
The issue affects Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 and its Server Core installation. All builds from these releases, regardless of architecture, are vulnerable unless patched.
Risk and Exploitability
The CVSS score of 7.0 indicates a high‑level severity for local privilege escalation. While the EPSS score is not available, the absence of an EPSS rating does not imply low exploit likelihood; the known exploitability remains high for attackers with local access. The product is not listed in the CISA KEV catalog, but that does not mitigate the risk. The vulnerability can be exploited by locally authenticated users, requiring only that the attacker gain local access to the system. In the absence of a published public exploit, defensive measures must rely on prompt patching.
OpenCVE Enrichment