Impact
A use‑after‑free flaw in the Windows Management Instrumentation service allows a local, authorized user to elevate privileges on the affected system. The vulnerability arises when an application or user re‑uses a handle to an object that has already been freed, enabling the attacker to execute code with higher privileges. This can culminate in full administrative control of the machine, as the flaw permits arbitrary code execution in a privileged context. The weakness is identified as CWE‑416.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022 and Server 2025, including all Server Core installations of these editions.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating a high impact if exploited. The EPSS score is not available, so the likelihood of exploitation in the wild remains uncertain. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local; an attacker must be an authorized user with access to the machine. The exploitation path involves manipulating WMI objects or services to trigger the use‑after‑free, after which the attacker can run code with elevated privileges.
OpenCVE Enrichment