Junglewise Threat Intelligence

CVE-2026-42981: Microsoft Windows Performance Monitor integer underflow remote code execution

CVE-2026-42981 · Severity: high · CVSS 8.1 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A vulnerability exists in Windows Performance Monitor, a tool used to track and analyze system resource usage. An unauthorized attacker could exploit this flaw over a network to run malicious code on a target system. This could lead to a complete compromise of the affected machine, potentially resulting in data theft or service disruption.

Technical details

An integer underflow (CWE-191) vulnerability exists in the Windows Performance Monitor component. The flaw is triggered when the application fails to properly validate input data, leading to a wrap or wraparound condition during memory allocation or buffer management. An unauthenticated attacker can exploit this over the network to achieve remote code execution. While the attack vector is network-based, the CVSS score reflects a high attack complexity, suggesting specific environmental conditions or timing may be required for successful exploitation. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Performance Monitor

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats