Impact
The vulnerability is a use‑after‑free flaw in the Windows Modern Execution Server that allows a malicious program running under a normal user account to corrupt the memory of the service and gain elevated local privileges. This flaw can be exploited to obtain system or administrative rights on the affected host, compromising the confidentiality, integrity, and availability of the system. The weakness is classified as CWE‑416 (Use After Free).
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2016 (including Server Core), 2019 (including Server Core), 2022, and 2025 (including Server Core).
Risk and Exploitability
The CVSS score of 7 indicates a high severity problem. EPSS data is not available, but the flaw is not listed in CISA’s KEV catalog. The likely attack vector is local, requiring an authorized attacker (a user with standard privileges on the host) to execute malicious code that triggers the use‑after‑free in the Modern Execution Server. Once triggered, the attacker can elevate privileges and execute actions with elevated rights on the compromised machine.
OpenCVE Enrichment