Impact
Use‑after‑free in Microsoft COM for Windows allows an authorized attacker to gain elevated local privileges. The flaw arises when an application incorrectly manages memory for a COM object, releasing it before all references are cleared. An attacker who can run code with the same user account can exploit the dangling pointer to execute arbitrary instructions with higher privilege, thereby compromising the integrity of the target system.
Affected Systems
Affected systems include Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and Windows Server 2022 and 2025 (including Server Core installations). The vulnerability is present in the default Windows deployments that include the COM subsystem.
Risk and Exploitability
With a CVSS score of 7, this vulnerability presents a moderate severity. The EPSS score is not available, and it is not listed in CISA’s KEV catalog. The exploitation requires a local, authorized user context. Attackers can trigger the use‑after‑free by executing a crafted payload within an application that utilizes the vulnerable COM interfaces, resulting in privilege escalation.
OpenCVE Enrichment