Impact
A use‑after‑free flaw in the Windows Win32k kernel driver allows an authorized local attacker to gain higher privileges than the attacker currently possesses by abusing a freed memory reference. The vulnerability can lead to unauthorized code execution with elevated rights, potentially compromising the confidentiality, integrity, or availability of the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server editions 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022 and 2025 are impacted. All of these platforms expose the vulnerable Win32k component in either x86, x64 or arm64 configurations.
Risk and Exploitability
The CVSS score of 7 indicates a medium to high severity flaw; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local, authorized user, meaning that an employee or malware already executing on the system could exploit the bug to raise its privileges. The lack of remote exploitation factors keeps the overall risk moderate, yet the local privilege escalation could enable a wide range of subsequent attacks on the compromised host.
OpenCVE Enrichment