Impact
The reported use‑after‑free flaw exists in the Windows Desktop Window Manager (DWM) Core Library. When the library frees a memory region and subsequently reuses it in an incorrect manner, an authorized attacker can execute arbitrary code with elevated privileges. The vulnerability allows privilege escalation for an attacker who already has some level of access to the target system and can exploit the DWM subsystem over a network connection.
Affected Systems
Microsoft Windows 11 Version 23H2 (both x64 and arm64 builds) and Microsoft Windows Server 2025, including Server Core installations, are affected as listed in the security advisory. The flaw is active whenever the DWM Core Library is loaded on those versions.
Risk and Exploitability
The CVSS score is 7.1, reflecting moderate severity, while the EPSS score is below 1%, indicating a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to be authorized or have locally elevated access to the machine so that the use‑after‑free condition can be triggered, typically through a privileged network session or a compromised user account with sufficient rights to interact with DWM.
OpenCVE Enrichment