Executive brief
A security vulnerability exists in Windows Media components that could allow a user with basic access to a computer to gain full administrative control. By exploiting a timing issue in how the system handles media resources, an attacker can bypass security restrictions to access sensitive data or modify system settings. This poses a significant risk to the integrity of the operating system and the confidentiality of user information.
Technical details
A race condition (CWE-362) and subsequent use-after-free (CWE-416) vulnerability exist in Windows Media due to improper synchronization when accessing shared resources. An attacker with low-privileged local access can exploit this flaw by executing a specially crafted application that triggers concurrent execution conflicts. Successful exploitation allows the attacker to gain SYSTEM-level privileges on the local machine. The vulnerability affects multiple versions of Windows 11, and Microsoft has released security updates to address the issue.
Affected products
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory