Executive brief
A security vulnerability exists in the core of the Windows operating system that could allow a user with limited access to gain full administrative control. This type of flaw is often used by attackers who have already gained a foothold on a system to expand their reach, potentially leading to the theft of sensitive data or the installation of persistent malware. Organizations should apply the latest Windows security updates to protect their workstations and servers.
Technical details
An improper access control vulnerability (CWE-284) exists within the Windows Kernel. The flaw allows a locally authenticated attacker with low privileges to execute a specially crafted application to bypass security restrictions and elevate their privileges to SYSTEM level. The attack vector is local, requiring no user interaction and having low complexity. Microsoft has released security updates to address this issue across affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2022 All versions
- Microsoft Windows Server 2025 All versions
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.