Executive brief
A security vulnerability has been identified in the core of the Microsoft Windows operating system. This flaw allows a user who already has basic access to a computer to gain full administrative control. Such an exploit could lead to the unauthorized installation of software, data theft, or the complete compromise of the affected system.
Technical details
An integer underflow (CWE-191) and associated heap-based buffer overflow (CWE-122) exist within the Windows NT OS Kernel. The vulnerability is triggered when the kernel incorrectly handles specific integer calculations, leading to a memory wrap or wraparound condition. An attacker with low-privileged local access can exploit this flaw without any user interaction to execute code in kernel mode. Successful exploitation results in a complete loss of confidentiality, integrity, and availability as the attacker gains SYSTEM-level privileges. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows NT OS Kernel
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory