Impact
Use‑after‑free vulnerability in Windows Error Reporting permits an attacker with user‑level access to gain higher privileges on the same machine. The flaw is a classic memory‑corruption issue identified as CWE‑416 and can be triggered by malformed error-reporting data processed by the privileged component.
Affected Systems
Microsoft Windows 10 (feature updates 1607 through 22H2), Windows 11 (releases 23H2 to 26H1), and Windows Server 2012 through 2025, including core installations, are affected. These systems run the Windows Error Reporting components that contain the vulnerable code.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, so exploitation is not known to be widely available yet. The likely attack vector is local; an attacker with authorized user access can exploit the use‑after‑free to elevate privileges to system level without needing remote access.
OpenCVE Enrichment