Impact
Use after free in Windows Web Platform Storage can let a local attacker elevate privileges on an affected system. The flaw arises when a freed resource is accessed again, allowing the attacker to execute code with higher privileges than originally granted.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2019 (including Server Core), 2022, and 2025 (including Server Core) are affected. The vulnerability applies to 32‑bit, 64‑bit, and ARM64 builds as listed in the CPE data.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating moderate severity. It has no EPSS score available and is not listed in the CISA KEV catalog, meaning no publicly documented exploits have been reported. The likely attack vector requires a local user with authorized access who can execute code that triggers the use‑after‑free, resulting in privilege escalation on the same machine.
OpenCVE Enrichment