Executive brief
A security vulnerability exists in the Windows service responsible for installing and managing applications (AppX Deployment Service). An attacker who already has basic access to a computer could exploit a timing issue to gain full administrative control over the system. This could allow them to access sensitive files, install malicious software, or disrupt business operations.
Technical details
A race condition (CWE-362) exists in the Windows AppX Deployment Service (AppXSVC) due to improper synchronization when handling shared resources during application deployment. An attacker with low-privileged local access can exploit this vulnerability by timing specific execution threads to interfere with service operations. Successful exploitation allows the attacker to gain elevated system privileges. The attack requires the attacker to win a race condition, making the complexity high, but it does not require user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions including Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory