Impact
The vulnerability is a use‑after‑free flaw within the Windows Win32K graphics subsystem that allows an authorized local attacker to gain higher privileges on the affected system. The flaw falls under CWE‑416, indicating that freed memory can still be accessed and manipulated. Successful exploitation can lead to malicious code running with elevated rights, potentially allowing the attacker to install malware, modify system settings, or otherwise compromise the host.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 (both full and server core installations). The affected builds include x86, x64, and arm64 variants as noted by the corresponding CPE entries.
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as high severity. The EPSS score of 2% indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation activity in the wild to date. The most likely attack vector is a local, authenticated user initiating an operation that triggers the use‑after‑free in Win32K, subsequently elevating privileges on the machine.
OpenCVE Enrichment