Executive brief
A security vulnerability has been identified in Windows OLE, a core technology that allows applications to share and link data like documents and spreadsheets. An attacker could exploit this flaw over a network to run unauthorized code on a target system. If successful, this could lead to a full system takeover, data theft, or service disruption. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.
Technical details
A type confusion vulnerability (CWE-843) exists in the Windows Object Linking and Embedding (OLE) component. The flaw occurs when the system accesses a resource using an incompatible type, which can be leveraged by an unauthenticated attacker to achieve remote code execution. While the attack vector is network-based, the complexity is rated as high, suggesting specific conditions or configurations may be required for successful exploitation. Microsoft has addressed this vulnerability in the July 2026 security updates for affected versions of Windows 10, Windows 11, and Windows Server 2012 R2.
Affected products
- Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 Versions 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 R2 All installations
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory