Impact
This vulnerability is a use‑after‑free error in the Microsoft Install Service that can allow a locally authenticated attacker to run code with elevated privileges. The weakness is mapped to CWE‑416, reflecting a failure to protect freed memory, which could lead to execution of arbitrary instructions. As a result, a user who can invoke the installer process may obtain administrative rights on the affected system, compromising confidentiality, integrity, and availability across the local environment.
Affected Systems
Affected systems include Microsoft Windows 10 versions 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, the Windows 11 23H2 build, Windows Server 2022, and Windows Server 2025 (including Server Core). No additional vendors or product lines are listed.
Risk and Exploitability
The CVSS score for this issue is 7, indicating substantial severity. EPSS data is not available, so the likelihood of exploitation in the wild is unknown, and the vulnerability is currently not listed in CISA’s KEV catalog. The likely attack vector is local, requiring an authorized attacker with legitimate user or administrator access to the target machine. Exploitation would involve triggering the use‑after‑free in the installer, which could lead to privilege escalation with no known mitigations besides patching.
OpenCVE Enrichment