Impact
A use‑after‑free flaw (CWE-416) in the Microsoft QUIC implementation allows an unauthorized attacker to execute arbitrary code on the affected system. The flaw can lead to full system compromise, granting the attacker control over confidentiality, integrity, and availability of the machine.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including the Server Core installation). The affected builds include both x64 and arm64 architectures depending on the release version.
Risk and Exploitability
The CVSS score of 9.8 classifies this as a critical level risk. The EPSS score of < 1% indicates a very low probability of exploitation at the time of analysis, yet the high severity and lack of KEV listing still demand urgent attention. The likely attack vector is a remote network attacker sending malicious QUIC packets to the target. Given the nature of the flaw, exploitation requires only network access to the QUIC endpoint, with no additional user interaction required.
OpenCVE Enrichment