Executive brief
A vulnerability exists in Windows Performance Monitor, a tool used to track and analyze system resource usage. An unauthorized attacker could exploit this flaw over a network to run malicious code on a target system. This could lead to a complete compromise of the affected machine, potentially resulting in data theft or service disruption.
Technical details
An integer underflow (CWE-191) vulnerability exists in the Windows Performance Monitor component. The flaw is triggered when the application fails to properly validate input data, leading to a wrap or wraparound condition during memory allocation or buffer management. An unauthenticated attacker can exploit this over the network to achieve remote code execution. While the attack vector is network-based, the CVSS score reflects a high attack complexity, suggesting specific environmental conditions or timing may be required for successful exploitation. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Performance Monitor
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory