Executive brief
A security vulnerability exists in the Microsoft Windows Program Compatibility Assistant Service, which is responsible for ensuring older software runs correctly on newer versions of the operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability (CWE-367) exists within the Microsoft Program Compatibility Assistant (PCA) Service. The flaw occurs when the service improperly validates file or memory states before performing a privileged operation, allowing a local attacker to swap resources between the check and the execution. To exploit this, an attacker must have local access and the ability to execute code with low privileges. Successful exploitation allows the attacker to gain SYSTEM-level privileges, leading to a complete compromise of confidentiality, integrity, and availability. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory