Impact
Use after free vulnerabilities in the Windows Key Distribution Center (KDC) enable an attacker with authorized access to execute arbitrary code on a target machine. The flaw occurs when the KDC incorrectly frees a memory block that is still referenced, allowing the attacker to trigger execution over a network connection.
Affected Systems
Affected systems include Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 as well as their Server Core variants. The CVE lists these specific product families; no narrower version range is specified.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of < 1 % suggests a low probability of exploitation at the time of analysis. The vulnerability is not currently listed in the CISA KEV catalog. Attackers must possess authorized access to the KDC service and use a network connection to trigger the use‑after‑free condition, resulting in remote code execution.
OpenCVE Enrichment