Executive brief
A security vulnerability exists in the Windows Virtual Filtering Platform, a component used to manage network traffic for virtual machines and containers. An authorized user on the network could exploit this flaw to cause a system crash or disrupt network services. This would result in a denial of service, potentially impacting the availability of hosted applications and corporate operations.
Technical details
This vulnerability is classified as a use-after-free (CWE-416) within the Windows Virtual Filtering Platform (VFP). An attacker must be authenticated (low privilege) and reach the target over the network to trigger the flaw. Due to high attack complexity, the exploit requires specific timing or environmental conditions to successfully reference memory after it has been freed. Successful exploitation leads to a denial-of-service (DoS) condition, typically manifesting as a system crash or service interruption. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory