Impact
A use‑after‑free flaw in the Capability Access Management Service (camsvc) allows an attacker who has already obtained some level of local access to obtain higher privileges on the affected Windows systems. The bug is a classic memory corruption vulnerability (CWE‑416) that, once triggered, can enable the attacker to run arbitrary code with elevated rights, thereby compromising the confidentiality, integrity, and availability of the host. The description confirms the routine mitigations are insufficient to prevent escalation beyond the current user privileges.
Affected Systems
The vulnerability affects a broad set of Microsoft Windows releases, including Windows 10 versions 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, Windows Server 2019, Windows Server 2022, and Windows Server 2025. All standard architectures for these editions are impacted.
Risk and Exploitability
The CVSS score of 7.0 indicates a medium to high severity risk, while the EPSS score is not available, suggesting no recent exploitation data is publicly indicated. The vulnerability is not listed in the CISA KEV catalog, but it requires the attacker to have local authorized access, which may be easier by exploiting other weaknesses or social engineering. Because of the local privilege escalation nature, the impact can be significant if an attacker obtains administrative rights on the target machine.
OpenCVE Enrichment