Impact
The vulnerability is a double free flaw in the Windows Registry that enables an authorized attacker to elevate privileges over a network. The flaw can be triggered by corrupting registry data handling, resulting in memory corruption that may be leveraged to gain higher privileges. The associated weakness is CWE-415, a classic double free vulnerability that permits control over memory usage and subsequent privilege escalation.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including both standard and Server Core installations.
Risk and Exploitability
This issue carries a CVSS score of 7.1, indicating moderate to high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a network‐based interaction where an attacker with local or remote privileges sends malicious registry commands to trigger the double free. While exploitation requires some level of authorization, the impact—unauthorized privilege escalation—makes it a significant risk if not remediated.
OpenCVE Enrichment