Impact
Use after free in the Windows SMB Client allows an attacker to execute code on the host without authentication. The vulnerability permits full compromise of the affected machine over the network. The weakness corresponds to CWE-416.
Affected Systems
The flaw applies to Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025, including Server Core installations. Only the arm64 and x64 builds of Windows 11 are listed as affected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity for remote code execution. EPSS data are not available, so the current probability of exploitation is unknown, but the vulnerability is not currently in CISA KEV. Based on the description, the likely attack vector is the SMB protocol over the network, requiring an unauthenticated attacker with network access to trigger the use‑after‑free. Official remediation is available through Microsoft security updates.
OpenCVE Enrichment