Impact
The vulnerability is a use‑after‑free flaw in Windows Modern Device Management (MDM). An authorized user with local access can exploit the flaw and gain higher privileges. This can allow the attacker to execute malicious code with administrative rights, compromising system integrity and confidentiality.
Affected Systems
Affected editions include Microsoft Windows 10 versions 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Microsoft Windows Server 2019, 2022 and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score is 7, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector requires the attacker to be an authorized local user; no network exposure is required. Because the flaw is a use‑after‑free, it can be triggered through normal MDM operations, making it potentially easy to exploit once the user has local access.
OpenCVE Enrichment