Impact
A use‑after‑free flaw in the Win32k graphics subsystem of Windows 11 allows a local attacker, who already has valid user credentials, to corrupt kernel memory and execute arbitrary code with elevated privileges. This can lead to full system compromise, exposing all confidential data and tampering with configuration, thereby affecting confidentiality, integrity, and availability.
Affected Systems
The affected products are Microsoft Windows 11 version 24H2 (arm64), version 25H2 (arm64), and version 26H1 (x64).
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate to high severity. The EPSS score is unavailable, so no current exploitation probability is defined, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is local and requires an authorized attacker who can run code on the target machine. Exploitation requires the use‑after‑free condition in Win32k, which gives the attacker privileged access to the system memory, thereby enabling privilege escalation.
OpenCVE Enrichment