Impact
A use‑after‑free flaw in the Audio Video Control Transport Protocol enables an authenticated local attacker to elevate privileges. The vulnerability allows the attacker to execute code after the protocol’s memory object has been freed, resulting in a privilege escalation on the affected machine.
Affected Systems
Microsoft Windows 11 24H2, 25H2 (arm64) and 26H1 (x64) as well as Windows Server 2025, including Server Core installations, are impacted. The flaw exists in the AVCTP implementation shipped with these operating systems.
Risk and Exploitability
The CVSS score of 7 indicates a moderate severity rating, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation likelihood is uncertain. The attack vector is local: an authorized user or process must trigger the use‑after‑free in AVCTP to gain higher privileges. A successful exploit would allow the attacker to elevate privileges on the local system, potentially compromising confidentiality, integrity, and availability of local resources.
OpenCVE Enrichment