Loading vulnerability details…
CVSS v3.1
7.1
EPSS
0.45%
Published
Jul 8, 2025
Modified
Jul 15, 2025
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (21)
References (1)