Impact
Use after free in Windows Internet Connection Sharing (ICS) allows an authorized local attacker to gain higher privileges than they originally had. The flaw permits code execution or manipulation of system resources with elevated rights, potentially giving the attacker full control over the affected machine, which compromises confidentiality, integrity, and availability. The vulnerability is a use‑after‑free related to CWE‑416.
Affected Systems
Affected by Microsoft in Windows 10 versions 1607, 1809, 21H2, 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Windows Server 2016, 2019, 2022, and 2025, including Server Core installations. All listed builds are impacted.
Risk and Exploitability
The CVSS score of 7 indicates a high severity local privilege escalation, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. The attack vector is inferred to be local, requiring an authorized user or a malicious process on the host to trigger the use‑after‑free and elevate privileges.
OpenCVE Enrichment