Executive brief
Windows Performance Monitor, a tool used to analyze system performance and resource usage, contains a critical security flaw. An unauthorized attacker could exploit this vulnerability over a network to gain control of the system and execute malicious code. This could lead to a complete compromise of the affected server or workstation, resulting in data theft or operational disruption.
Technical details
An integer underflow (wraparound) vulnerability exists in Windows Performance Monitor, identified as CWE-190. The flaw is triggered when the component improperly handles specific numerical inputs, leading to memory corruption. An unauthenticated attacker can exploit this over the network, though the CVSS 'Attack Complexity: High' metric suggests specific timing or environmental conditions may be required for successful exploitation. Successful exploitation allows for remote code execution (RCE) in the context of the affected service. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Performance Monitor
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory