Impact
Use-after-free in the Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally. The flaw occurs when the component holds a reference to freed memory, enabling the attacker to exploit the invalid pointer and execute code with higher privileges. This weakness is classified as CWE-416 and could allow a local user to gain administrative or system level rights.
Affected Systems
The vulnerability affects Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2016, Server Core, Windows Server 2019 (including Core), Windows Server 2022, and Windows Server 2025 (including Core).
Risk and Exploitability
The CVSS base score of 7 indicates a high severity and the vulnerability is exploitable only by an attacker with local authorized access. EPSS data is unavailable, and the flaw is not in the CISA Known Exploited Vulnerabilities catalog, so the exploitation probability appears limited. However, because it permits privilege escalation, it poses a significant risk to system integrity if an adversary gains local access.
OpenCVE Enrichment