Impact
An authorized user can exploit a use‑after‑free bug in the Windows Win32K graphics subsystem to gain system or administrative privileges. The flaw corrupts kernel memory, enabling arbitrary code execution at elevated privileges and compromising confidentiality, integrity, and availability for the system.
Affected Systems
The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), as well as Windows Server 2016, Server 2019, Server 2022 and Server 2025, including both standard and Server Core installations.
Risk and Exploitability
With a CVSS score of 7, the issue poses high severity local exploitation risk. The EPSS score of 0.00219 indicates a very low exploitation probability and it is not listed in the CISA KEV catalog, suggesting limited public exploitation data. The attack requires local user access and relies on a use‑after‑free condition in the Win32K kernel driver. If an attacker succeeds, privileged code can run, facilitating lateral movement or complete system compromise.
OpenCVE Enrichment