Impact
The vulnerability is a use‑after‑free flaw within the Windows Wireless Networking component that allows a local attacker who already has authorized access to the system to gain elevated privileges. As a result, malicious code can execute with higher permissions, potentially undermining the security of the entire machine. The weakness maps to CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2019, 2022, and 2025 (including Server Core installations) are all impacted. The vulnerability resides in the wireless networking subsystem present on these systems.
Risk and Exploitability
The CVSS score of 7.0 signals a high severity vulnerability, while the EPSS score is not available, making the precise likelihood of exploitation uncertain. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a local attacker who is already authenticated or otherwise authorized on the machine, meaning the attack vector is local. Given the high severity and local nature, the overall risk is moderate to high for environments where users with local access could be adversaries or compromise the machine through other means.
OpenCVE Enrichment