Impact
A use‑after‑free condition in the Windows Desktop Window Manager Core Library (CWE‑416) allows an attacker who already has local user credentials to run code with elevated privileges. By accessing memory that has already been freed, malicious code can corrupt internal data structures or bypass security checks, giving the attacker system‑level rights that can be used to install malware, modify system configuration, or persist a foothold.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Microsoft Windows Server 2022 and 2025 (including Server Core installations). Each of these releases includes the DWM Core Library component affected by this use‑after‑free flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability that can be exploited locally by an authenticated user. Because exploitation requires local access, the threat is confined to systems where a user can log on. The EPSS score of <1% suggests a low probability of active exploitation, and the vulnerability is not listed in CISA’s KEV catalog, meaning widespread current exploitation is not documented. Nonetheless, the combination of a high severity score and the local privilege escalation vector warrants timely mitigation.
OpenCVE Enrichment