Executive brief
A security vulnerability exists in the Windows Rich Text Edit component, which is used by many applications to display and edit formatted text. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new user accounts with full rights.
Technical details
A double free vulnerability (CWE-415) exists in the Windows Rich Text Edit Control. The flaw is triggered when the component incorrectly handles memory allocation during the processing of specific text content. An attacker with low-privileged local access can exploit this by inducing a user to interact with a specially crafted application or document, leading to arbitrary code execution with elevated system privileges. The attack requires local access and some user interaction, and it is characterized by high complexity due to the memory management conditions required for successful exploitation. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.19045.7291
- Microsoft Windows 11 up to (excluding) 10.0.22631.7079
- Microsoft Windows Server 2012 R2 All versions
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.9140
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.8755
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.5139
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft released the initial advisory.
- 2026-06-01: other: Advisory description was updated by the vendor.