Executive brief
A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system that helps applications run and interact with the system. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative permissions. This could allow them to bypass security restrictions, access sensitive data, or install malicious software that would otherwise be blocked.
Technical details
A use-after-free vulnerability (CWE-416) exists in the Windows Runtime (WinRT) component of Microsoft Windows. The flaw is triggered when the system continues to use a memory pointer after it has been freed, which can be manipulated by a local attacker with low privileges. Successful exploitation requires the attacker to win a race condition or navigate high complexity execution flow (AC:H) to achieve local privilege escalation (LPE). If successful, the attacker can gain SYSTEM-level privileges on the affected host. Microsoft has released security updates to address this issue across supported versions of Windows 11 and Windows Server 2025.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.26200.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory