Impact
A use‑after‑free flaw in the Windows Universal Disk Format (UDFS) file system driver allows an authorized local user to reference freed memory, which can lead to arbitrary code execution and elevation of privileges. The weakness is documented as CWE‑416 and results in a local privilege escalation scenario.
Affected Systems
The vulnerability affects multiple Windows desktop and server releases, including Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server versions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS base score of 7 indicates moderate‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, so the precise likelihood of exploitation is uncertain. Based on the description, it is inferred that an attacker would need to be able to interact with removable media that are formatted using UDFS to trigger the exploit. The local scope limits the impact to the affected device, but success would grant full system privileges to the attacker.
OpenCVE Enrichment