Impact
The vulnerability is a use‑after‑free flaw in the Windows DNS service that allows an authorized local attacker to gain elevated privileges. If exploited, the attacker can execute arbitrary code or raise the security context of a process, undermining the integrity of the host.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2; Microsoft Windows 11 releases 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server releases 2012 R2, 2016, 2019, 2022, and 2025, including both full and Server Core installations, are affected by this flaw.
Risk and Exploitability
The flaw has a CVSS score of 7, indicating a high potential impact. No EPSS score is publicly available and the vulnerability is not listed in the CISA KEV catalog, but the local attack requires an authorized attacker who already has some level of access. If an attacker can authenticate to the machine, they can exploit the use‑after‑free to execute code with elevated privileges, enabling lateral movement or further privilege escalation within the network.
OpenCVE Enrichment