Impact
Use After Free in Windows NDIS allows an authorized attacker to elevate privileges over a network. The flaw is a use‑after‑free condition in NDIS driver code. An attacker who can send crafted packets to a vulnerable system can trigger the use‑of‑freed memory to execute arbitrary code with elevated privileges, thereby compromising the integrity and confidentiality of the machine. The weakness is classified as CWE-416.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, 22H2, Windows 11 23H2, 24H2, 25H2, 26H1, Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, including their Server Core installations. All supported architectures listed are affected.
Risk and Exploitability
CVSS score 7.1 indicates a moderate severity. EPSS score is not available, and the vulnerability is not included in CISA's KEV. Attack vector is inferred to be network‑based; an attacker who already has valid credentials or network access to the target must send specially crafted network traffic to trigger the use‑after‑free. Because the flaw requires an authorized context, the resource of exploitation is limited to systems exposed to networks that use NDIS drivers. The risk is moderate but tangible, especially for critical infrastructure that relies on default NDIS functionality.
OpenCVE Enrichment