Impact
The vulnerability is a use-after-free flaw in Windows Modern Device Management (MDM). An attacker who has authorized access to MDM can trigger the flaw to gain elevated privileges on the local machine. The flaw is categorized as CWE‑416. Attackers who succeed can potentially gain system‑level access, enabling them to install software, alter configurations, or exfiltrate data. The flaw does not provide remote code execution but raises the privilege level of the attacker on that device.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score is 7, indicating high severity. The EPSS score is not available, meaning the current exploit probability assessment is unknown. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an authorized attacker with local access, the attack vector is local and exploitation likely requires administrative privileges. Given the high severity and the lack of automatic detection, organizations should treat this as a critical patching item.
OpenCVE Enrichment