Impact
Use after free in the Windows Devices Human Interface component permits a local user with authorization to execute arbitrary code as SYSTEM. The flaw is a classic use‑after‑free (CWE‑416) where memory that has already been freed is accessed again, allowing the attacker to control program flow and gain elevated privileges. This could enable installation of malware, bypass of security controls, or persistence on the affected machine.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, 22H2, Windows 11 releases 23H2, 24H2, 25H2, 26H1, and all supported Windows Server versions 2016, 2019, 2022, 2025 (both full and Server Core installations) are impacted. The vulnerability exists in the Human Interface device drivers that process input from keyboards, mice, and other HID devices.
Risk and Exploitability
CVSS score of 7 indicates medium severity; the EPSS score is below 1%, suggesting a very low probability of exploitation. The issue is not listed in the CISA KEV catalog, indicating that widespread attacks are not currently documented. An attacker would need local authorized access to the target machine, typically through device usage. No network or remote exploitation vector is documented, so the risk remains confined to local privilege escalation scenarios.
OpenCVE Enrichment