Executive brief
A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system that helps run modern applications. An attacker could exploit this flaw to gain higher-level permissions on a target system than they should normally have. This could allow an unauthorized user to interfere with system operations or access restricted data across a network.
Technical details
This vulnerability is characterized as a race condition (CWE-362) and a potential use-after-free (CWE-416) within the Windows Runtime (WinRT). The flaw occurs due to improper synchronization when multiple threads or processes attempt to access shared resources concurrently. An unauthenticated attacker can exploit this over the network, though the attack complexity is rated as high, likely requiring specific timing or environmental conditions to successfully trigger the race. Successful exploitation allows for elevation of privilege, potentially granting the attacker unauthorized access or control over the affected system. Microsoft has released security updates to address this issue across various versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
- 2026-07-14: advisory