Impact
Use‑after‑free in Windows Win32K lets an authorized attacker overwrite memory structures and gain elevated privileges on systems reachable over a network.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1. The same issue affects Microsoft Windows Server 2012 R2, 2016, 2019, 2022 and 2025 with both full and Server Core installations.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential impact if exploited. With no EPSS data available and its absence from the CISA KEV list, the current exploitation risk is unclear, yet the vulnerability can be triggered by an authorized attacker with network access to a system running a vulnerable Win32K component. A privileged escalation could allow the attacker to execute code or gain unrestricted access to system resources.
OpenCVE Enrichment