Executive brief
A security vulnerability exists in the Windows Server Update Service (WSUS) component of Windows 11. This service is responsible for managing and distributing software updates across corporate networks. If exploited, a user who already has limited access to a computer could gain full administrative control, potentially allowing them to access sensitive data or disrupt system operations.
Technical details
A use-after-free (CWE-416) vulnerability exists within the Windows Server Update Service (WSUS) component. The flaw is triggered when the service incorrectly manages memory objects, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level privileges. While the attack complexity is rated as high—likely requiring specific timing or race conditions—a successful exploit allows the attacker to gain SYSTEM-level privileges. Microsoft has released security updates to address this issue in Windows 11 version 26H1.
Affected products
- Microsoft Windows 11 version 26H1 up to (excluding) 10.0.28000.1836
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Microsoft released the security update guide for this vulnerability.