Impact
Use‑after‑free vulnerabilities occur when a program attempts to use memory that has already been freed. In this case, the flaw resides in the Windows Media component and allows an attacker with local system access to execute arbitrary code under the current user’s security context. The result is a local privilege escalation that can enable the attacker to gain higher privileges on the affected machine. This specific weakness is classified as CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2016, 2019, 2022, and 2025—including their Server Core installations—are listed as vulnerable. All affected releases are referenced by the Windows Security Response Center. The vulnerability is present in systems that allow the Windows Media feature to run locally.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high severity. Because the EPSS score is not provided, the probability of exploitation in the wild cannot be determined from the available data. The vulnerability is not currently catalogued by CISA as a known exploited vulnerability. To exploit the flaw an attacker must have local user access and must be able to trigger the Windows Media processing path; no specific network‑based vector is indicated by the data, so the attack is presumed to be local. Even in the absence of public exploits, the nature of the flaw grants a local adversary the ability to elevate privileges, which warrants prompt remediation.
OpenCVE Enrichment