Executive brief
A security vulnerability exists in the core of the Windows operating system that could allow a user with limited access to gain full administrative control over the computer. This type of flaw is typically used by attackers who have already gained a foothold on a system to deepen their access and bypass security boundaries. If exploited, an attacker could view sensitive data, change system settings, or install malicious software across the entire machine.
Technical details
A local privilege escalation vulnerability exists in the Windows Kernel due to improper input validation leading to an out-of-bounds read and heap-based buffer overflow. An attacker with low-privileged local access can exploit this flaw to execute code in kernel mode. Successful exploitation allows the attacker to escape security sandboxes and gain SYSTEM-level privileges. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server; patches are available via Microsoft's Security Update Guide.
Affected products
- Microsoft Windows 10 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2019 All editions
- Microsoft Windows Server 2022 All editions
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory