Impact
This vulnerability is a use‑after‑free flaw within the Windows File History Service. It allows an attacker who already has local authorization to elevate privileges, potentially taking complete control of the affected system. The flaw lies in improper handling of deallocated memory when processing File History operations, which an attacker can exploit to execute arbitrary code with elevated rights.
Affected Systems
Affected releases include Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016 and 2019 (both standard and Server Core editions). Systems running any of these operating systems without the vendor’s latest security update are susceptible.
Risk and Exploitability
The CVSS base score of 7 indicates moderate severity. The EPSS score of 0.27% indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is unlikely at this time. The likely attack vector is local: an authorized user must execute a specially crafted file or trigger the File History Service to cause the use‑after‑free condition. Successful exploitation permits local privilege escalation, which can lead to full control over the system and compromise any data or services of which the system is responsible.
OpenCVE Enrichment