Impact
The vulnerability is a double free in the Windows Credential Guard subsystem that permits an attacker who already has authorized local access to elevate privileges on the target machine. By corrupting heap structures during normal operation, the flaw can lead to total compromise of the host, updating the integrity and confidentiality of all data managed by the operating system.
Affected Systems
Affected products include Microsoft Windows 11 24H2, Microsoft Windows 11 25H2, Microsoft Windows 11 26H1, and Microsoft Windows Server 2025 (both Standard and Server Core installations). All listed versions are impacted by the double free condition in the Credential Guard components.
Risk and Exploitability
The CVSS score is 8.2, indicating a high severity of the flaw. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that no explosive exploitation is currently documented. The likely attack vector is local, requiring authorized access; an attacker must manipulate memory during the Credential Guard execution path to trigger the double free. Because the flaw affects a fundamental security subsystem, the potential impact is full system compromise once exploited.
OpenCVE Enrichment