Impact
A use‑after‑free flaw in the Windows Security Health Service enables an authorized local attacker to run code with elevated privileges. The vulnerability arises when memory that has already been freed is accessed again, allowing the attacker to hijack the control flow and obtain higher rights. This is a classic use‑after‑free weakness (CWE‑416) that can compromise system integrity by giving the attacker access to administrative functions.
Affected Systems
Affected systems include Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025, including Server Core installations.
Risk and Exploitability
The vulnerability scores a CVSS of 7, indicating a high severity local risk. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The likely attack vector is a local authorized user or malware running on the system; the attacker must be able to trigger the use‑after‑free condition, but no remote exploitation path is described.
OpenCVE Enrichment