Impact
A use‑after‑free vulnerability in the Windows License Manager allows an authorized local attacker to elevate privileges. This flaw is identified as CWE‑416 and enables an attacker to run code with administrative authority on the compromised machine. The impact is restricted to the local user context; remote exploitation has not been described.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including Server Core deployments. No other operating systems are listed as affected.
Risk and Exploitability
The CVSS score of 7 classifies the flaw as medium severity for local privilege escalation. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation at this time. The vulnerability is not catalogued in the CISA KEV list, and no public exploit code is available. The likely attack vector is local, requiring an attacker to be authenticated on the target machine. Successful exploitation would grant the attacker administrative privileges on the affected system.
OpenCVE Enrichment