Impact
Use‑after‑free in the Windows Error Reporting component permits a local user with authorized access to create a privilege‑escalation condition. The flaw leads to execution of code at higher privilege levels, thereby compromising system integrity and exposing the machine to further exploitation. The weakness is classified as CWE‑416, indicating unsafe use of freed memory.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2 and 26H1, as well as Windows Server 2025 (both full and Server Core installations) are vulnerable. The affected builds include arm64 ARM processors for Windows 11 24H2 and 25H2, and x64 for Windows 11 26H1, with all server variants operating on standard CPU architectures.
Risk and Exploitability
With a CVSS score of 7, the vulnerability is considered high severity. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA's KEV catalog, indicating no publicly known exploit at this time. The attack vector appears to be local, requiring an authorized user to invoke error reporting paths that trigger the use‑after‑free condition; therefore, the risk is elevated on systems with broad user privileges or insufficient segregation.
OpenCVE Enrichment