Microsoft Windows 10
cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*
A use-after-free vulnerability has been identified in the Windows Internal System User Profile component. This vulnerability allows an authorized attacker to elevate privileges locally. It affects multiple versions of Windows 10 and Windows 11, as well as Windows Server 2025.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access within the system.
Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5099539 for Windows 10 and KB5101650 for Windows 11. For Windows Server 2025, the relevant update is also available through the Microsoft Update Catalog, with details in KB5099536.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.