Impact
A use‑after‑free flaw in the Windows Win32K graphics subsystem allows an attacker who has local execution privileges to trigger memory corruption. The vulnerability can be leveraged to gain elevated local privileges, potentially granting access to protected resources and enabling execution of arbitrary code within the system context. The weakness is classified as CWE‑416, an improper use of a freed object.
Affected Systems
Microsoft Windows 11 releases 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 (including Server Core) are affected. The vulnerability is present in the Win32K component of these operating systems and applies to the specified build versions. There is no information on earlier or later versions.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity, while no EPSS data is available and the issue is not listed in the CISA KEV catalog. The flaw requires an attacker with local access and the ability to trigger the use‑after‑free condition, such as via a malicious executable or crafted user interface input. Once triggered, the attacker can achieve local privilege escalation, raising the risk of additional lateral movement or further compromise.
OpenCVE Enrichment