Executive brief
A security vulnerability exists in the Windows Hotpatch Monitoring Service, a component used to manage system updates without requiring a reboot. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists within the Windows Hotpatch Monitoring Service. The flaw is triggered when the service improperly handles memory buffers, allowing an attacker to write data beyond the end of an allocated buffer. To exploit this, an attacker must first have local access to the system with low-level privileges. Successful exploitation allows the attacker to execute code with elevated system privileges, potentially leading to a full compromise of the host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.
- 2026-06-09: patched: Security updates made available via MSRC.