Executive brief
A security vulnerability has been identified in the Windows Kernel, the core component of the Microsoft Windows operating system. This flaw allows a user who already has basic access to a computer to gain full administrative control over the system. Such an exploit could be used by attackers to bypass security restrictions, access sensitive data, or install persistent malicious software.
Technical details
This vulnerability is classified as a Use-After-Free (CWE-416) within the Windows Kernel. An attacker with local access and low-level privileges can exploit this flaw to execute code in kernel mode. The vulnerability is triggered when the kernel incorrectly manages memory objects, allowing an attacker to reference memory after it has been freed. Successful exploitation results in a complete privilege escalation (LPE), typically to SYSTEM level, and carries a high impact on confidentiality, integrity, and availability. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2026-07-14: advisory: Microsoft Security Update Guide published.