Impact
A use‑after‑free flaw exists in the Windows TCP/IP stack that can be triggered by an authorized attacker. The flaw allows the attacker to manipulate memory after an object has been freed, potentially leading to the execution of arbitrary code with elevated privileges on the local machine. The primary impact is the ability for the attacker to gain higher privileges, which can compromise system integrity and confidentiality.
Affected Systems
The vulnerability affects Microsoft Windows operating systems including Windows 10 versions 1607 to 22H2, Windows 11 versions 23H2 through 26H1, as well as Windows Server editions from 2012 to 2025, including core installations.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits but a non‑negligible risk. The likely attack vector is a network‑based interaction with the TCP/IP stack; however, the description infers that the attacker must have authorized network access to the target. Exploitation would require crafting a payload that triggers the use‑after‑free condition, which can lead to privilege escalation on the affected system.
OpenCVE Enrichment