Executive brief
A security vulnerability exists in the Windows component responsible for processing Rich Text (RTF) content, which is commonly used in word processing and email applications. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.
Technical details
A double free vulnerability (CWE-415) exists within the Windows Rich Text Edit component. The flaw is triggered when the system attempts to free the same memory location twice during the processing of specially crafted rich text content. To exploit this, an attacker must first have local access to the target system with low-level privileges and convince a user to interact with a malicious file or application. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Rich Text Edit
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD.
- 2026-05-12: advisory: Microsoft published the security update guide.