Executive brief
A security vulnerability exists in the core engine of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control. This could allow them to steal sensitive data, install malicious software, or disrupt business operations.
Technical details
An integer underflow (wraparound) vulnerability exists within the Windows NT OS Kernel. The flaw is triggered when the kernel incorrectly handles integer calculations, leading to memory corruption or logic errors. An attacker with low-privileged local access can exploit this vulnerability without any user interaction. Successful exploitation allows the attacker to escape their current security context and gain SYSTEM-level privileges. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows NT OS Kernel
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory