Impact
The vulnerability is a use‑after‑free flaw in the Windows Image Acquisition (WIA) component, identified as CWE‑416. It permits a user who already has authorized local access to corrupt memory and gain higher privileges on the host. The flaw can be triggered by a malicious file processed by WIA, enabling the attacker to execute code with elevated rights, potentially compromising the entire system.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both standard and Server Core installations. The specific build numbers are those listed in the CNA vendor/product information.
Risk and Exploitability
The CVSS score of 7.0 places this issue in the high‑severity range, while no EPSS or KEV flag indicates it has not yet been widely exploited in the wild. The attack requires local authorized access, but the use‑after‑free nature means that once triggered, privilege escalation can occur without additional network interaction. Consequently, the risk to affected systems is significant for environments where users have sufficient access to files read by WIA.
OpenCVE Enrichment