Executive brief
A security vulnerability exists in Microsoft XML Core Services, a component used by Windows to process XML data. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the affected system, potentially leading to data theft or the installation of malicious software.
Technical details
A use-after-free vulnerability (CWE-416) exists in Microsoft XML Core Services (MSXML). The flaw is triggered when the system improperly handles objects in memory, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must first have local access to the system with low-level user privileges. Successful exploitation allows the attacker to elevate their privileges to a higher level, potentially gaining full system control. The attack complexity is rated as high, suggesting specific timing or environmental conditions are required for a successful exploit.
Affected products
- Microsoft Windows 10 Version 1607 10.0.14393.0 to 10.0.14393.9339
- Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2012 6.2.9200.0 to 6.2.9200.26226
- Microsoft Microsoft XML Core Services (MSXML)
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory