Impact
The vulnerability is a use‑after‑free condition in Windows Host Guardian Service that permits a local attacker to elevate privileges, potentially achieving full system control. This flaw falls under CWE‑362 (Race Condition) and CWE‑416 (Use After Free). The impact is a local privilege escalation that could allow the attacker to bypass normal security boundaries and execute arbitrary code with administrative rights. The user or process that can trigger the flaw is required to be authenticated or to have certain local privileges, but once the exploit succeeds, the attacker can gain higher privilege privileges on the affected machine.
Affected Systems
Affects Microsoft Windows 10 Version 1809, 21H2, and 22H2; Windows 11 Version 23H2, 24H2, 25H2, 26H1; Windows Server 2019, Server Core; Windows Server 2022; Windows Server 2025 and its Server Core edition. All these operating systems contain the Windows Host Guardian Service component that is vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity for a local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no active exploitation reported yet. Nevertheless, because the flaw requires an authorized local user, the effective attack vector is local but still poses significant risk for users with privileged access. The mitigation focus is on applying the security update as soon as possible to eliminate the vulnerability. If the update cannot be applied immediately, disabling or uninstalling the Host Guardian Service would break the exploit path until a fix is available. The CVSS score supports pressing for a prompt patch.
OpenCVE Enrichment