Executive brief
A security vulnerability has been identified in the Windows Kernel, the core component of the Microsoft Windows operating system. An attacker who already has basic access to a system could exploit this flaw to gain higher-level administrative privileges. This could allow them to bypass security restrictions or cause system instability, potentially impacting business operations and data integrity.
Technical details
A use-after-free vulnerability (CWE-416) exists in the Windows Kernel. The flaw is triggered when the kernel attempts to use memory that has already been freed, which can be exploited by a locally authenticated attacker with low privileges. Successful exploitation requires the attacker to win a race condition (High Attack Complexity) but can result in local privilege escalation or a denial-of-service (system crash). Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide.