Impact
The reported issue is a use‑after‑free condition within the Windows Win32K graphics subsystem that can be abused by an attacker who already has some authorized presence on the network to gain higher privileges. The flaw does not specifically mention arbitrary code execution, but it can provide the attacker with a mechanism to elevate privileges when exploited.
Affected Systems
Affected systems include Microsoft Windows 10 build 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, and 26H1; and the Windows Server family from 2012 through 2025, including Server Core installations, for both x86, x64 and arm64 as applicable.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high risk, while an EPSS score is not available, which means the likelihood of exploitation in the wild is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploitation. The information available implies the attacker must be authorized on the network, and the high severity suggests it should be treated as a priority.
OpenCVE Enrichment