Impact
The vulnerability is a use‑after‑free flaw in Windows HTTP.sys that permits an authorized attacker on the network to obtain privileges that exceed those assigned to the attacker. The flaw allows the malicious actor to execute code with elevated privileges, potentially compromising the entire system and any services running on it. The weakness is classified as CWE‑416 and can impact confidentiality, integrity, and availability of the affected systems.
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1 as well as Microsoft Windows Server 2025, including Server Core installations, are affected by the flaw.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability represents a high level of risk. Because the exploit requires an authorized attacker to access the target over a network, the attack vector is inferred to be network‑based. EPSS is not available, so the exploit likelihood cannot be quantified, and the flaw is not listed in the CISA KEV catalog. The use‑after‑free condition could allow local privilege escalation if the attacker controls network traffic to the vulnerable port.
OpenCVE Enrichment