Impact
A use‑after‑free flaw in the Windows Image Acquisition component allows an attacker who already has local access to gain elevated privileges on the affected system. The vulnerability is a classic use‑after‑free bug (CWE‑416) that can be triggered by manipulating image acquisition requests, enabling the attacker to execute code with higher authority than their original account.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1) and Windows Server 2012 through 2025, including both standard and server‑core installations.
Risk and Exploitability
The CVSS score of 7 indicates high severity, but the attack requires a local authorized user; therefore exploitation is plausible in environments where user accounts can execute image handling functions. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread active exploitation yet. The local elevation risk remains significant, especially in unpatched or misconfigured systems.
OpenCVE Enrichment