Impact
A use‑after‑free flaw in the Windows WebClient Service enables an authorized local attacker to gain higher privileges by corrupting memory. The vulnerability can allow escalation from a standard user role to an elevated role, potentially giving the attacker administrator‑level access. This flaw is a classic example of improper memory management (CWE‑416) with direct impact on confidentiality, integrity, and availability of the affected system.
Affected Systems
The issue affects multiple Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations. All relevant versions are listed in the CNA affected‑version data and in the provided CPE strings.
Risk and Exploitability
With a CVSS score of 7.8, this flaw is considered high severity but its exploitability is limited to local environments, as the attacker must already be authorized on the machine. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. The lack of an Internet‑bound attack vector reduces the likelihood of widespread exploitation, but any local user who can trigger the use‑after‑free condition could elevate privileges to full control of the host.
OpenCVE Enrichment