Executive brief
A security vulnerability exists in the Tablet Windows User Interface (TWINUI) component of Microsoft Windows, which handles various interface tasks and file associations. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A race condition (CWE-362) exists in the Tablet Windows User Interface (TWINUI) Subsystem due to improper synchronization when accessing shared resources. The vulnerability is reachable by a locally authenticated user with low privileges. By successfully exploiting this timing-based flaw, an attacker can achieve local privilege escalation (LPE), potentially gaining SYSTEM-level access. The issue affects a wide range of Windows client and server versions, including Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this synchronization issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched