Executive brief
A security vulnerability exists in the core drivers that manage how the Windows operating system interacts with hardware. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, the installation of malicious software, or a complete system takeover.
Technical details
A type confusion vulnerability (CWE-843) exists within Windows Kernel-Mode Drivers due to the improper handling of resources using incompatible types. The vulnerability is exploitable by a locally authenticated attacker with low privileges (PR:L) and requires no user interaction. By successfully exploiting this flaw, an attacker can achieve local privilege escalation (LPE), gaining SYSTEM-level access and full control over the affected host. Microsoft has released security updates to address this issue; users should apply the latest Windows cumulative updates to mitigate the risk.
Affected products
- Microsoft Windows Kernel-Mode Drivers
Timeline
- 2026-06-09: disclosed: Initial publication of the CVE record by Microsoft.
- 2026-06-09: advisory: Microsoft Security Response Center (MSRC) published the vulnerability details and update guide.