Executive brief
A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system used by applications to interact with the system. An authorized user on the network could exploit this flaw to gain higher-level administrative permissions than they should have. This could allow an attacker to take full control of affected Windows 11 or Windows Server 2025 systems, potentially leading to data theft or service disruption.
Technical details
A Use-After-Free (UAF) vulnerability (CWE-416) exists in the Windows Runtime component. The flaw can be triggered by an authenticated attacker with low privileges over a network, though the attack complexity is rated as high, suggesting specific timing or environmental conditions are required. Successful exploitation allows the attacker to achieve a scope change and elevate their privileges to a higher level (e.g., SYSTEM). The vulnerability affects various versions of Windows 11 and Windows Server 2025; Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD
- 2026-07-14: patched: Security updates made available by Microsoft