Impact
The Windows Bind Filter Driver contains a use-after-free flaw that allows an authorized local user to exploit a memory management bug and execute arbitrary code with elevated privileges; this is a classic CWE-416 vulnerability that can compromise the confidentiality, integrity, and availability of the affected system if the adversary can trigger the fault.
Affected Systems
The flaw affects Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Windows Server 2025, including Server Core installations; both x64 and ARM64 architectures are impacted, as indicated by the relevant CPE entries, and the vulnerability is present in the specified builds of the Bind Filter Driver.
Risk and Exploitability
The CVSS base score of 7 indicates a high‑severity local privilege escalation, the EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, implying no publicly known exploits at the time; an attacker must be locally authenticated and have the ability to interact with the affected driver, which suggests that the most likely attack vector is a legitimate user context—possibly a compromised account or a privileged service—preparing to trigger the use-after-free, and even without an existing exploit, the inherent severity warrants prompt remediation as there is no indication of a mitigation other than patching.
OpenCVE Enrichment