Impact
The vulnerability is a use‑after‑free bug in the Windows Remote Access Connection Manager that allows an attacker who already has authorized access on a local machine to gain elevated privileges. This flaw provides a pathway for local privilege escalation, allowing the attacker to potentially compromise the confidentiality, integrity, or availability of the compromised system. The weakness is formally categorized as CWE‑416.
Affected Systems
Affected are Microsoft Windows 10, 10.0 version 1607, 1809, 21H2, 22H2; Windows 11, 23H2, 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations. These include a wide range of desktop and server operating systems from Windows 10 1607 onward.
Risk and Exploitability
With a CVSS score of 7 the flaw is considered medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires local authorized access, it is not remotely exploitable, but once an attacker reaches the local system, the privilege escalation can be leveraged to bypass security controls. The attack vector is therefore likely to be a local attacker who can run code with nominal user privileges. Given the prevalence of the affected OS versions and the absence of a readily exploitable remote entry point, the risk remains moderate to high for systems with exposed Remote Access services or when the feature is enabled for users who should not have elevated rights.
OpenCVE Enrichment