Impact
A use‑after‑free bug in the Windows USB Video Driver enables an authorized local attacker to elevate privileges, potentially gaining admin privileges on the host. This flaw allows the attacker to execute arbitrary code after the driver frees memory, a classic example of a memory‑management vulnerability categorized as CWE‑416.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025 and its Server Core installation, are affected. The 24H2 and 25H2 releases target ARM64 platforms, while version 26H1 addresses x64 architectures.
Risk and Exploitability
The CVSS score of 7.0 classifies this as a high‑severity vulnerability. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, indicating a lack of confirmed widespread exploitation. The attack model requires the attacker to have local, authorized access to plug a USB video device and to deliver exploit code that triggers the use‑after‑free condition.
OpenCVE Enrichment