Executive brief
A security vulnerability exists in the Windows Application Identity (AppID) Subsystem, which is responsible for identifying and verifying the identity of applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new accounts with full user rights.
Technical details
A heap-based buffer overflow (CWE-122) exists within the Windows Application Identity (AppID) Subsystem. The vulnerability is triggered when the subsystem improperly handles memory allocation during application identity verification. An attacker with low-privileged local access can exploit this by sending specially crafted requests to the AppID service, leading to memory corruption. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue via the MSRC update guide.
Affected products
- Microsoft Windows
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory