Impact
The vulnerability is a double free bug in the Microsoft Graphics Component that allows an unauthorized network attacker to execute arbitrary code with system privileges. This flaw is a type of use‑after‑free (CWE-415) and, once triggered, grants the attacker total control over the affected Windows system. The description states that the attacker does not need local access, implying remote exploitation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server 2012 (including Server Core), 2012 R2, 2016, 2019, 2022 and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 9.8 denotes a critical severity. The EPSS score is not available, so the exploitation probability cannot be quantified, but the lack of a KEV entry suggests no confirmed public exploits yet. The attack vector is inferred as remote over a network; the double free can be triggered by crafted graphics data or remote client interaction, allowing an attacker to execute code with elevated privileges.
OpenCVE Enrichment