Executive brief
A security vulnerability exists in the Microsoft Windows Capability Access Management Service, which manages how applications access hardware features like cameras or microphones. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to unauthorized data access, the installation of malicious software, or a complete system takeover.
Technical details
A race condition (CWE-362) and potential use-after-free (CWE-416) vulnerability exists in the Capability Access Management Service (camsvc) of Microsoft Windows. The flaw stems from improper synchronization when multiple threads or processes access shared resources within the service. An attacker with low-privileged local access can exploit this timing issue to gain elevated system privileges. The vulnerability affects Windows 11 and Windows Server 2025, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.7623
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.7623
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.32230
Timeline
- 2026-01-13: advisory: Initial publication by Microsoft and NVD
- 2026-01-13: patched: Security updates released by Microsoft