Impact
A use‑after‑free flaw in the Windows kernel can allow an attacker to execute code with kernel privileges. The vulnerability enables memory corruption, giving the attacker the ability to gain elevated privileges beyond those originally granted. This can lead to full system control, data exfiltration, or persistence mechanisms when the exploit succeeds.
Affected Systems
Affected operating systems include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both full and Server Core installations).
Risk and Exploitability
The CVSS score of 7.1 reflects moderate‑high severity. EPSS data is not available, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a network‑based scenario that requires authorized access, meaning an attacker with valid credentials or existing local access could leverage the flaw to elevate privileges. The exploitation conditions involve triggering the use‑after‑free within the kernel, which is non‑trivial but feasible for an attacker with sufficient network privileges. The overall risk is elevated due to the potential for full kernel compromise if the flaw is exploited on an affected system.
OpenCVE Enrichment