Impact
The vulnerability is a double free in the Windows Display Enhancement Service that enables an authorized local attacker to gain elevated privileges. Because the bug allows memory corruption, a privileged user could cause arbitrary code execution with the system context, leading to a complete takeover of the affected host. The weakness is classified as CWE-415.
Affected Systems
Affected products include Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 in both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity for local privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires local authorization; an attacker with legitimate user credentials can trigger the double free by interacting with the Display Enhancement Service. The privilege escalation would allow the attacker to gain SYSTEM rights and control the system.
OpenCVE Enrichment