Executive brief
A vulnerability in the Windows Clipboard User Service, which manages copy-and-paste functionality across the operating system, could allow a user with basic access to take full control of the computer. By exploiting this flaw, an attacker who is already logged into a system can bypass security restrictions to gain administrative-level privileges. This could lead to the unauthorized installation of software, viewing or deleting sensitive data, or creating new accounts with full user rights.
Technical details
A command injection vulnerability (CWE-77) exists in the Windows Clipboard User Service due to improper neutralization of special elements used in a command. An attacker with local access and low-level privileges can exploit this by sending specially crafted input to the service, leading to the execution of arbitrary commands with elevated system privileges. The attack vector is local, requiring the attacker to already have an authorized account on the target machine, but it requires no user interaction. Microsoft has released security updates to address this issue in affected versions of Windows 11 and Windows Server 2025.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 up to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 up to 10.0.26200.8875
- Microsoft Windows Server 2025 10.0.26100.0 up to 10.0.26100.33158
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory