Executive brief
A security vulnerability exists in the Windows component responsible for isolating containerized applications. An attacker who already has basic access to a system could exploit this flaw to gain full administrative control. This could lead to unauthorized access to sensitive data, system-wide outages, or the installation of malicious software.
Technical details
A use-after-free (CWE-416) vulnerability exists in the Windows Container Isolation FS Filter Driver. The flaw is triggered when the driver incorrectly manages memory objects during file system operations related to container isolation. An attacker with local access and low-level privileges can exploit this condition to execute arbitrary code in kernel mode. Successful exploitation allows the attacker to achieve full SYSTEM privileges. Microsoft has released security updates to address this issue across affected versions of Windows 10 and Windows 11.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2, 26H1
Timeline
- 2026-04-14: advisory: Initial disclosure by Microsoft and NVD.