Impact
A double free bug in the Windows Secure Kernel Mode subsystem allows a local attacker with authorized access to gain elevated privileges on the system. This flaw is classified as a memory management error (CWE‑415) and can be exploited to execute code with higher privileges than the attacker originally possesses.
Affected Systems
Microsoft Windows 11 version 26H1 (x64).
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and the EPSS score of 0.00261 (0.26%) shows a very low probability of exploitation in the general population. The vulnerability not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local; an authorized user who can run code in kernel mode may trigger the double free and thus obtain elevated privileges. The lack of a publicly disclosed exploit at this time does not diminish the risk posed by the flaw, especially in environments where privileged processes run with inadequate isolation.
OpenCVE Enrichment