Executive brief
A security vulnerability has been identified in the Windows Remote Procedure Call (RPC) mechanism, a core component that allows different programs to communicate with each other. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to unauthorized access to sensitive data, the ability to install malicious software, or the disruption of critical business operations.
Technical details
A double-free vulnerability (CWE-415) exists in the Windows Remote Procedure Call (RPC) Interface Definition Language (IDL) processing. The flaw allows a locally authenticated attacker to execute code with elevated privileges by sending specially crafted requests to the RPC runtime. The attack vector is local, requiring the attacker to have low-privileged access to the target system prior to exploitation. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (SYSTEM-level access). Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched