Impact
Use after free in Windows Management Instrumentation allows an authorized attacker to gain higher privileges on the affected system. The flaw is a memory corruption bug that can lead to elevated privilege code execution, potentially compromising confidentiality, integrity, and availability. The weakness is classified as CWE‑416 (Use After Free).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, all installations that include the Windows Management Instrumentation service.
Risk and Exploitability
The CVSS score of 7.1 indicates a significant impact level. The EPSS score is not available, so the current likelihood of exploitation is unclear. The vulnerability is not listed in CISA publicly known exploited vulnerabilities. It is inferred that the attack vector requires an attacker with network access to the target’s WMI service; once the use‑after‑free is triggered, code can run with elevated privileges of the local user context.
OpenCVE Enrichment