Executive brief
A security vulnerability exists in the core of the Windows operating system that could allow a user with limited access to gain full administrative control. By exploiting how the system manages memory, an attacker who is already logged into a machine can bypass security restrictions to access sensitive data or disrupt operations. This poses a significant risk to the integrity and confidentiality of any affected workstation or server.
Technical details
This vulnerability is a use-after-free (UAF) condition within the Windows Kernel, though Microsoft also references CWE-122 (Heap-based Buffer Overflow) in their classification. An attacker must have local access to the system and valid low-privileged credentials to initiate the exploit. The attack complexity is rated as high, suggesting specific timing or system conditions are required to successfully trigger the memory corruption. If successful, the attacker can execute code with kernel-level privileges, leading to a complete compromise of the operating system's confidentiality, integrity, and availability.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory