Impact
A use‑after‑free flaw in Windows Modern Device Management (MDM) allows an authorized attacker to gain elevated local privileges. The vulnerability is a classic CWE‑416 issue that can lead to unauthorized code execution, manipulation of system settings, and full control over the affected machine. It directly compromises confidentiality, integrity, and availability for the user session in which the flaw is triggered.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2 and Windows 11 versions 23H2, 24H2, 25H2, 26H1 also affected. Windows Server 2019, 2022, 2025 and their Server Core installations are impacted as well. No specific service packs or build numbers are listed in the CNA details; all listed product editions are vulnerable.
Risk and Exploitability
The CVSS score of 7.0 indicates a high‑severity local privilege escalation. The EPSS score is not available, so the current exploitation probability remains unclear. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local: an attacker with prior authorized MDM access can trigger the use‑after‑free through a crafted MDM request or profile manipulation. No known exploits are publicly disclosed, but the flaw’s local nature means it can be used by any user who already has MDM credentials or a dangling MDM session.
OpenCVE Enrichment