Executive brief
A security vulnerability has been identified in the Windows kernel component responsible for managing graphics and windowing. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software.
Technical details
A double free vulnerability (CWE-415) exists in the Windows Win32K kernel-mode driver, specifically within the ICOMP component. The flaw is triggered when the system attempts to free the same memory location twice, which can be manipulated to corrupt kernel memory. An attacker with low-privileged local access can exploit this condition to execute code with SYSTEM privileges. The attack requires high complexity, likely due to the precise timing or memory grooming needed to successfully redirect execution flow. Microsoft has released security updates to address this issue across affected Windows 11 and Windows Server versions.
Affected products
- Microsoft Windows 11 Version 23H2 < 10.0.22631.6491
- Microsoft Windows 11 Version 24H2 < 10.0.26100.7623
- Microsoft Windows 11 Version 25H2 < 10.0.26200.7623
- Microsoft Windows Server 2022 < 10.0.20348.4648
- Microsoft Windows Server 2025 < 10.0.26100.32230
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched