Executive brief
A security bypass vulnerability exists in several versions of Microsoft Windows and Windows Server. An attacker with local access to a system could bypass certain security features, potentially allowing them to view or modify data they should not have access to. This could compromise the integrity of the operating system and the confidentiality of user information.
Technical details
A vulnerability classified as improper access control (CWE-284) exists within the Windows System component. The flaw allows an attacker with local access to the target machine to bypass security restrictions without requiring elevated privileges or user interaction. Successful exploitation can lead to a loss of confidentiality and integrity, though it does not directly impact system availability. The vulnerability affects multiple modern versions of Windows 11 and Windows Server, including the 2022 and 2025 editions. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
- Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
- Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft
- 2026-07-14: advisory: NVD record published