Impact
Use after free in the Windows Remote Access Connection Manager exposes a local privilege escalation flaw that allows an authenticated user to exploit a freed memory reference to execute code with elevated rights. This vulnerability can lead to full system compromise, enabling the attacker to obtain system‑level access, read or modify data, and disrupt services. The weakness is a classic Use After Free (CWE‑416).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 and their Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates high severity for local attackers who already possess authorized credentials. Because the EPSS score is not available, the exploitation probability cannot be quantified, and the vulnerability is currently not listed in CISA’s KEV catalog. Attackers would need local access and the vulnerability is exploitable via the Remote Access Connection Manager component; credentials or local user privileges are prerequisites.
OpenCVE Enrichment