Impact
A use‑after‑free condition in the Windows Embedded Mode Service allows an authorized local user to execute vulnerable code after the service frees memory, enabling the attacker to elevate privileges. The flaw is a classic memory corruption bug (CWE‑416) that can lead to SYSTEM‑level access and the ability to modify or exfiltrate data, install payloads, or otherwise compromise the host. The description explicitly states that the escalation is limited to users already authenticated on the machine.
Affected Systems
The vulnerability affects a broad range of Windows operating systems. Specifically, Windows 10 build 1607 through build 22H2, Windows 11 builds 23H2–26H1, as well as Windows Server editions 2016, 2019, 2022, and 2025, including their server core installations. All listed versions are susceptible.
Risk and Exploitability
The CVSS score of 7.0 indicates a medium‑to‑high risk rating, and while the EPSS score is unavailable, the lack of a public exploit suggests a moderate likelihood of exploitation. The attack requires local, authorized access and takes advantage of a memory corruption flaw in a privileged service. As the vulnerability is not listed in CISA’s KEV catalog, there is no confirmed active exploitation, but the potential for serious impact remains. Mitigation via a patch is the recommended path to eliminate the attack surface.
OpenCVE Enrichment