Impact
The vulnerability is a use‑after‑free in the Windows kernel that permits an attacker with some level of authorized access to raise their privileges, potentially allowing the attacker to evade restrictions and gain administrative or system level permissions. This flaw is identified as CWE‑416, which indicates that the code may reference freed memory after a release, leading to corruption or execution of arbitrary code at a higher privilege level. The stated effect is an elevation of privilege that can be exploited to perform further malicious actions on the target machine.
Affected Systems
The flaw affects Microsoft Windows 10 from build 1607 through 22H2, Windows 11 from 23H2 to 26H1, and all supported Windows Server releases from 2012 to 2025, including both core installations and full desktop editions where applicable. Systems running any of those specific versions are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is 7.1, which indicates a high severity rating. While the EPSS score is not provided, the lack of a KEV listing suggests that known exploits are not widely reported yet. Because the description indicates the vulnerability can be triggered over a network, an attacker would typically need network access and some form of authorized interaction with the target. The risk is therefore present for exposed systems, especially those with open remote services or management interfaces. Until mitigation steps are taken, administrators should consider the potential for privilege escalation by malicious insiders or remote adversaries.
OpenCVE Enrichment