Impact
This vulnerability is a use‑after‑free flaw in the Windows Accounts Control component that allows an attacker with authorized local access to obtain elevated privileges on the system. The memory safety error is classified as CWE‑416 and results in the attacker gaining higher level rights than originally granted.
Affected Systems
Affected operating systems include Microsoft Windows 10 version 1607 through 22H2, Windows 11 versions 23H2 to 26H1, and Windows Server editions 2016, 2019, 2022, and 2025, including Server Core installations. The flaw impacts x86, x64, and ARM64 builds.
Risk and Exploitability
The CVSS base score of 7 indicates a high severity requiring local access and an authorized user account to exploit. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no widespread active exploitation known. An attacker would need to create or leverage an existing authorized account; by exploiting the use‑after‑free in Accounts Control they can elevate that account to full administrative privileges, potentially compromising the entire system.
OpenCVE Enrichment