Impact
The vulnerability is a use‑after‑free flaw in the Windows Internet Connection Sharing (ICS) component that can cause the kernel to execute code supplied by an attacker. The flaw allows an attacker to trigger the memory corruption and run arbitrary code in the context of the local system, resulting in full compromise of the affected device. This is a high‑severity, denial of integrity and confidentiality weakness, reflected in the CWE‑416 classification.
Affected Systems
Affected versions include multiple Windows client and server releases: Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, all of which are listed by the CNA as vulnerable. The vulnerability exists across both x86 and x64 builds and includes ARM64 variants for Windows 11.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of 0.00909 indicates a very low, but non‑zero, exploitation likelihood, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote over the network, as the flaw is triggered by unauthorized network interactions with the ICs service. An attacker with network access to a machine running any of the listed Windows versions could exploit this flaw to gain full system compromise.
OpenCVE Enrichment