Impact
The flaw is a use-after-free condition within the Windows Image Acquisition component that allows an attacker with local authorization to elevate privileges. Exploitation can grant the user higher level rights, compromising the confidentiality, integrity, and availability of the affected system. The weakness corresponds to CWE-416, indicating improper deallocation and use of freed memory.
Affected Systems
Protected are Microsoft Windows 10 (builds 1607, 1809, 21H2, 22H2), Windows 11 (builds 23H2, 24H2, 25H2, 26H1), and multiple Server editions including 2012, 2012 R2, 2016, 2019, 2022, and 2025. Each of the listed versions is impacted as enumerated by Microsoft.
Risk and Exploitability
With a CVSS score of 7, the vulnerability is considered high severity. The EPSS is not supplied, but the notes indicate that an authorized local attacker can exploit the flaw, meaning the attack vector is likely local. The vulnerability is not currently listed in the CISA KEV catalog, which suggests that widespread exploitation has not yet been observed. Because the flaw requires local access and sends crafted input to the WIA module, attackers would need to have a privileged account or privileged device I/O to trigger the use-after-free. Once triggered, the attacker can gain elevated privileges, enabling them to install software, modify system settings, or compromise other accounts.
OpenCVE Enrichment