Impact
Windows Accounts Control contains a use‑after‑free bug that can be exploited locally by an authorized user to elevate privileges. The flaw arises when the system frees a memory object that is still referenced, allowing the attacker to manipulate execution flow and gain higher privilege levels than originally granted. Identified as CWE‑416, the vulnerability can enable an attacker to run code with elevated rights, modify system settings, and potentially compromise the entire machine.
Affected Systems
Affected clients include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Microsoft Windows Server releases 2016, 2019, 2022 and 2025 (both regular and Server Core installations).
Risk and Exploitability
The CVSS score of 7 indicates a high likelihood of significant impact. No EPSS data is published, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; it requires an authorized user or one who can execute code on the target system. The use‑after‑free condition can be triggered by manipulating privileged account operations within the Accounts Control component, giving the attacker elevated system privileges.
OpenCVE Enrichment