Impact
A use‑after‑free flaw in the Windows AF_UNIX Socket Provider allows an attacker who has local authority to gain elevated privileges. By reusing freed memory, the attacker can corrupt control data, leading to execution of privileged code in the context of the target process. The weakness is a memory corruption that may enable arbitrary code execution, as identified by CWE‑416. The impact is an unauthorized privilege escalation within the affected Windows environment.
Affected Systems
Systems affected include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core editions).
Risk and Exploitability
The CVSS score of 7 indicates a high severity for local privilege escalation. EPSS is not available, so the current estimate of exploitation probability is unknown, but the lack of a KEV listing suggests no widespread public exploitation yet. Since the flaw requires an authorized attacker, the primary attack vector is local. An adversary who can run code on the machine can trigger the use‑after‑free and raise privileges, potentially compromising the entire system.
OpenCVE Enrichment