Impact
The vulnerability is a use‑after‑free error in the Windows Virtual Trusted Platform Module driver. An attacker who already has authorized access can trigger the flaw to execute code with higher privileges, potentially gaining full system control. This type of flaw, classified as CWE‑416, can lead to local privilege escalation, allowing the attacker to bypass security boundaries.
Affected Systems
The flaw affects multiple Microsoft Windows builds: Windows 10 versions 1809, 21H2 and 22H2; Windows 11 releases 23H2, 24H2, 25H2 and 26H1 (for both arm64 and x64 architectures); and Windows Server editions 2019, 2022 and 2025, including Server Core installations. All affected products are listed in the Microsoft update guide linked in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high risk, and the EPSS score is not available, so the current exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely local; an authorized user or process would need to invoke specific functions in the vTPM driver to trigger the use‑after‑free. Exploitation would allow the attacker to gain elevated privileges on the compromised system. Because no public exploits are reported and the terrain requires local access, the likelihood of a widespread external attack is limited, but the impact within a compromised environment is severe.
OpenCVE Enrichment