Executive brief
A security vulnerability has been identified in Windows Management Services, a core component used for managing and monitoring Windows systems. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the device. This could allow them to access sensitive data, install malicious software, or disrupt business operations.
Technical details
A privilege escalation vulnerability exists in Windows Management Services due to a use-after-free condition combined with a race condition (CWE-362). The flaw is triggered when the service improperly synchronizes shared resources, allowing an attacker with low-privileged local access to execute code with elevated system permissions. Exploitation requires the attacker to win a timing race, making the attack complexity high, but a successful exploit results in a full security scope crossing. Microsoft has released security updates to address this issue across affected Windows 10, 11, and Server versions.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory