Impact
The vulnerability is a use‑after‑free flaw in the Windows Broadcast DVR User Service that permits a local, authorized attacker to gain higher privileges on the affected system. Because the service incorrectly accesses memory after it has been freed, an attacker can manipulate control flow or execute arbitrary code, resulting in elevated local privileges and potentially enabling the compromise of other processes or persistent footholds.
Affected Systems
Affected Windows operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2016 and 2019, including Server Core installations.
Risk and Exploitability
This flaw carries a CVSS score of 7, indicating a medium‑to‑high severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires local, authorized access, so a user who already has access to the target machine can trigger the use‑after‑free and gain elevated privileges. Without a patch, a local attacker can use the flaw to run code as SYSTEM, which can lead to full system compromise.
OpenCVE Enrichment