Impact
A use‑after‑free flaw in the Windows ALPC subsystem allows an authorized local user to obtain higher privileges. The vulnerability causes code to execute after an object has been freed, matching the memory corruption weakness identified as CWE‑416. Attackers who can run processes on the target machine could trigger the flaw to manipulate kernel behavior and gain administrative rights.
Affected Systems
Microsoft Windows operating systems from Windows 10 version 1607 through Windows 11 version 26H1 and across several Server editions – 2012, 2012 R2, 2016, 2019, 2022 and 2025 – are affected. All standard and server‑core installations of these releases, across x86, x64, arm64, and arm64 variants, have the vulnerability present.
Risk and Exploitability
The CVSS score of 7 indicates a high severity consistent with local privilege escalation. The EPSS score is not presently available, and the flaw is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed yet. However, because the attack requires only local authorization, it can be performed by users with limited permissions who then elevate to system level. The lack of a known remote vector means immediate patching of this local flaw is critical to prevent an attacker from leveraging the use‑after‑free condition.
OpenCVE Enrichment