Impact
Use‑after‑free flaw in the Win32K component of Windows allows an authorized attacker to elevate privileges locally. This memory corruption vulnerability (CWE‑416) can lead to unintended privilege escalation on the affected system.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607 and 1809, as well as Windows Server 2012 (including Server Core) and Windows Server 2012 R2 (including Server Core), Windows Server 2016, and Windows Server 2019 (including Server Core). These operating systems contain the vulnerable Win32K component, and the flaw is present from the specified release versions onward.
Risk and Exploitability
With a CVSS score of 7, the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating no publicly documented exploits at this time. The attack vector is local: an attacker must already have authorized access on the target machine to trigger the use‑after‑free. Once the vulnerability is exploited, the attacker could gain elevated privileges, potentially leading to full system compromise.
OpenCVE Enrichment