Impact
This vulnerability is a use‑after‑free flaw in the Windows Connected User Experiences and Telemetry component. When a privileged process allocates a memory block for telemetry information and subsequently frees it, an attacker who can execute code within the same user context can abuse the freed memory to write or execute data of their choosing. The result is a local escalation of privilege, allowing the attacker to gain higher privileges, potentially reaching administrator or SYSTEM level on the affected machine.
Affected Systems
Microsoft Windows products that are listed as affected include Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; as well as Windows Server 2016, 2019, 2022, and 2025, including both full and Server Core installations. All x86, x64, and ARM64 builds for these releases are impacted.
Risk and Exploitability
The CVSS score for the flaw is 7, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local: an authorized or user‑level attacker must already have some form of legitimate access to the target system. Once the attacker can deliver code to the affected component, the use‑after‑free can be leveraged to gain local administrative rights. No remotely triggered exploit is documented, so the risk is confined to environments where an attacker can run code on the target machine.
OpenCVE Enrichment