Impact
The vulnerability is a use‑after‑free flaw located in Windows Connected User Experiences and Telemetry that allows an attacker with local authorized access to elevate privilege. Because the flaw is only exploitable after an object has been freed but still referenced, an attacker can manipulate the system to execute arbitrary code at a higher privilege level, thereby compromising the integrity of the operating environment.
Affected Systems
Affected systems include Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2022 and Windows Server 2025. These products all contain the vulnerable implementation of connected user telemetry services.
Risk and Exploitability
The CVSS score of 7 indicates a high‑severity vulnerability, but no EPSS score is available and the issue is not listed in the CISA KEV catalog. The exploit is local, requiring the attacker to already possess authorized access. The lack of a public exploit and the local‑only nature of the attack suggest a moderate risk of exploitation, yet the potential privilege escalation warrants prompt action.
OpenCVE Enrichment