Impact
The vulnerability is a use‑after‑free flaw in the Windows kernel that allows an authorized attacker with local access to elevate privileges. It is categorized as CWE‑416. Successful exploitation could result in the attacker gaining higher privileges or administrative rights, compromising the integrity of the affected system and potentially enabling further attacks.
Affected Systems
Affected products include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations. Both 32‑bit and 64‑bit Windows architectures, as well as ARM architecture for Windows 11, are impacted.
Risk and Exploitability
The CVSS score of 7 indicates a medium severity. The EPSS score is currently unavailable, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring an attacker to be on the compromised machine with some privileged context to submit a crafted request that triggers the use‑after‑free in the kernel.
OpenCVE Enrichment