Impact
A use‑after‑free flaw in the Windows Network Driver Interface Specification (NDIS) permits an attacker with authorized network access to elevate privileges. This flaw can allow the attacker to execute code or commands with higher privileges than originally granted, potentially enabling further compromise of the system.
Affected Systems
Affected systems include Microsoft Windows 10 version 1607, 1809, 21H2, 22H2, Windows 11 version 23H2, and Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025, in both standard and server core installations.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, while the absence of an EPSS score and lack of listing in the CISA KEV catalog suggest the exploitation probability is not well characterized. The likely attack vector involves a network‑connected attacker who already has legitimate access to the target device, leveraging the use‑after‑free condition in the NDIS driver to gain elevated privileges.
OpenCVE Enrichment