Executive brief
A security vulnerability exists in the Windows Clip Service, a component responsible for managing clipboard data and license services. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive files, install malicious software, or disrupt business operations.
Technical details
This vulnerability is characterized as a race condition (CWE-362) and a use-after-free (CWE-416) within the Windows Clip Service (ClipSVC). The flaw stems from improper synchronization when multiple threads access shared resources, leading to memory corruption. An attacker with low-privileged local access can exploit this timing issue to execute code with elevated system privileges. The attack requires the attacker to win a race condition, making the exploit complexity high, but it requires no user interaction. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory