Impact
This vulnerability is a use‑after‑free defect in Windows Security Center. It permits an attacker who already has local user access to take advantage of a freed memory reference in order to execute privileged code. As a result, a non‑privileged user could gain rights equivalent to a local administrator, potentially leading to full system compromise. Based on the description, it is inferred that the attack vector is from an authorized local user.
Affected Systems
The affected systems are Microsoft Windows 11 24H2, Windows 11 25H2, Windows 11 26H1, and Windows Server 2012 (including the Server Core installation).
Risk and Exploitability
The CVSS score of 7 indicates high severity. The EPSS score of < 1% indicates a very low exploitation probability, and the flaw is not yet listed in the CISA KEV catalog, suggesting that exploitation is not widespread at present. The exploit requires local user privileges and functions via the Security Center component, so the attack path is limited to a machine where the user is already authenticated or has physical access. Based on the description, it is inferred that the attack vector is local to the machine.
OpenCVE Enrichment