Executive brief
A security vulnerability exists in the Windows UI Automation Manager, a component that helps software interact with the user interface. An attacker who already has basic access to a computer could exploit a timing error to gain full administrative control over the system. This could allow them to install programs, view or delete sensitive data, or create new accounts with full user rights.
Technical details
A race condition (CWE-362) exists in the UI Automation Manager (uiamanager.dll) due to improper synchronization when accessing shared resources. An attacker with local access and low privileges can exploit this flaw by carefully timing execution to interfere with system processes. Successful exploitation allows the attacker to elevate privileges to SYSTEM level. The attack requires high complexity due to the precise timing needed to win the race condition, but it does not require user interaction.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Microsoft released an advisory and update guide.