Impact
The kernel streaming WOW thunk service driver contains a use‑after‑free bug that enables an attacker who already has local access to the system to gain elevated privileges. By freeing a kernel memory buffer and then accessing it again, the attacker can corrupt kernel state or execute arbitrary code with elevated rights, compromising the confidentiality or integrity of the entire machine. This vulnerability is classified as CWE‑416 and carries a medium‑severity CVSS score of 7.
Affected Systems
This flaw affects a wide range of Microsoft Windows operating systems. The affected products include Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 23H2, 24H2, 25H2, 26H1, and the 23H2 variant; and all Windows Server editions from 2012 through 2025, whether in server core or full installation mode. The specific CPE strings indicate both 32‑bit and 64‑bit architectures, including ARM64 for some Windows 11 builds.
Risk and Exploitability
The vulnerability is local and requires an authorized attacker who can execute code on the affected machine to trigger the use‑after‑free condition. The CVSS score of 7 indicates a moderate risk, and the EPSS score is currently unavailable, providing no additional insight into exploitation likelihood. The flaw is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Organizations should treat it a medium‑severity concern, given the potential for privilege escalation if the flaw remains unpatched.
OpenCVE Enrichment