Impact
This vulnerability is a use‑after‑free flaw in the Windows Hello component, allowing an authorized local attacker to execute code with higher privileges. By exploiting a freed object that remains in memory, the attacker can manipulate the execution flow and run arbitrary instructions, potentially taking full control of the affected system. The weakness is classified as CWE‑416, representing improper deallocation of resources.
Affected Systems
The flaw affects Windows 11 versions 23H2, 24H2, 25H2, and 26H1. All architectures listed (arm64 and x64) for these releases are impacted, as indicated by the relevant CPE entries. Users running any of these builds require remediation.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating a high severity and significant risk to confidentiality, integrity, and availability. No EPSS score is available, so the exact likelihood of exploitation remains unknown, and the issue is not yet listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an authenticated or otherwise authorized user to trigger the use‑after‑free through Windows Hello authentication or management functions.
OpenCVE Enrichment