Impact
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. The flaw is a race condition combined with a use‑after‑free bug, enabling control of privileged processes or actions that normally require higher rights. The impact is a local escalation of privilege from the level of an attacker who already has basic local access.
Affected Systems
Affected devices include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2016, 2019, 2022, 2025, with both full and Server Core installations. These operating systems are impacted by the vulnerability as listed in the CNA affected‑product entries.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating moderate severity. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog. The likely attack vector requires a local attacker with some legitimate access to the machine. Successful exploitation could grant the attacker elevated privileges, allowing them to execute arbitrary code, modify system settings, or establish persistence. Due to the local nature of the flaw, the threat is significant for users with administrative privileges or those who can elevate privileges through local misconfigurations.
OpenCVE Enrichment