Impact
The vulnerability is a use-after-free in Windows Credential Providers that lets a legitimate local user, capable of executing code in the context of the credential provider, trigger a memory reuse error and elevate their privileges. The flaw arises from an incorrect check of a dangling pointer, which aligns with CWE-416 use after free. Attackers can potentially exploit the flaw to gain administrator-level rights on the target machine, enabling arbitrary code execution with system privileges and compromising the confidentiality, integrity, and availability of the affected device.
Affected Systems
The issue affects Microsoft Windows 11 releases 23H2, 24H2, 25H2, 26H1 on both arm64 and x64 architectures and the Windows Server 2025 operating system, including both Server Core installation and full installation versions.
Risk and Exploitability
The CVSS score of 7 indicates a moderate-to-high risk. EPSS information is not available, so the precise likelihood of exploitation remains unknown, though the flaw is not currently listed in the CISA KEV catalogue. The attack vector is local; an attacker must first gain access to the target machine—physically or via remote compromise—and then execute code that triggers the credential provider bug. Once triggered, the flaw would allow privilege escalation to an elevated user, enabling further compromise of the system.
OpenCVE Enrichment