Impact
Use after free within the Windows kernel allows an authorized local attacker to elevate privileges. This flaw corresponds to CWE-416 and gives full system privileges to a user who already has local access, undermining the isolation between user space and kernel space. The exploitation potential is to gain admin rights, allowing modification of system settings, installation of malware, and persistence with elevated privileges.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (both full and server core installations).
Risk and Exploitability
CVSS score of 7.0 indicates medium-high severity. The EPSS score of < 1% suggests a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been reported. The likely attack vector is local; the attacker must already have authorized local access to the target machine. With the flaw, a user can perform a kernel mode use-after-free, enabling privilege escalation. Because exploitation requires local access, the risk is primarily in environments with privileged users or malware that can gain local foothold.
OpenCVE Enrichment