Impact
This vulnerability is a classic use‑after‑free bug in Windows’ Win32K graphics subsystem. If an attacker can run code locally, the flaw allows malicious input to be processed after memory has been freed, giving the attacker the ability to execute privileged operations on the system. The problem is confined to users who have some level of local access; it cannot be exploited remotely based on the available information. The weakness corresponds to CWE‑416.
Affected Systems
Affected releases include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1. Windows Server 2016, Server 2019, Server 2022, and Server 2025 (both full and Server Core editions) are also impacted. Systems that run any of these Windows families should verify which product and build they are using to determine the risk level.
Risk and Exploitability
The CVSS score of 7.0 indicates a high‑to‑medium severity. Because the flaw requires local execution of crafted input, the EPSS value is not provided and no KEV listing exists, suggesting that widespread or automated attacks are not yet demonstrated. The likely attack vector is local; an attacker would need to engage a user or a process capable of running arbitrary code to trigger the exploit. In the absence of an immediate fix, the focus should be on preventing local code execution and limiting privileged local users until the vendor releases a fix.
OpenCVE Enrichment