Impact
The vulnerability is a use‑after‑free flaw in the Graphic Fonts subsystem that allows an attacker with local access to execute a memory corruption exploit. When an authorized user causes the fault, the system can inadvertently grant elevated administrative privileges as a result of improper memory handling consistent with CWE‑416. The impact is a local privilege escalation that could enable unrestricted access to data and system controls.
Affected Systems
Affected products include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server from 2012 through 2025, both standard and Server Core installations. These builds run on varied processor architectures such as x86, x64, and arm64.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity for local attacks, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. Because the attacker must be authenticated and the flaw originates from user‑controlled font rendering, the exploitability is moderate; however, once successful, it provides full administrative rights.
OpenCVE Enrichment