Impact
A use‑after‑free flaw exists in the Windows Desktop Window Manager (DWM) Core Library that enables an attacker who already has local user credentials to elevate their privileges. The vulnerability allows the malicious code to access memory that has already been freed, potentially corrupting internal data structures and bypassing security checks. The result is elevated system rights, which can be used to install malware, modify system configuration, or persist a foothold.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Microsoft Windows Server 2022 and 2025 (including Server Core installations). Each of these releases includes the DWM Core Library component that is impacted by the use‑after‑free condition.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability. Because the attack requires local access and an authenticated user, the threat is limited to systems where a user can log on. The EPSS score of 2% indicates a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, so widespread active exploitation is currently not documented. Nevertheless, the combination of a local privilege escalation vector and the high CVSS score makes timely mitigation advisable.
OpenCVE Enrichment