Impact
This vulnerability is a use‑after‑free in the Windows win32k graphical subsystem. If an authorized user or local attacker can trigger misuse of freed memory, they can gain execution privileges with the rights of the local account. The flaw is categorized as Use After Free (CWE‑416).
Affected Systems
The flaw impacts Microsoft Windows 10 versions 1809, 21H2, 22H2 on both 32‑bit and 64‑bit builds. Windows 11 versions 23H2, 24H2, 25H2, and 26H1 are affected, including ARM64 and x64 architectures. Server editions, including Windows Server 2019, Windows Server 2022, and Windows Server 2025, as well as their Server Core installations, are also subject to the escalation. All architectures listed in the CPE entries are affected.
Risk and Exploitability
The CVSS base score of 7 indicates high severity for local impact. EPSS data is not available, so the exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no widely deployed exploit is currently known. The risk is highest for systems with privileged accounts or poor segmentation, as the flaw requires an authorized local presence. Applying the vendor patch is the primary risk mitigant.
OpenCVE Enrichment