Executive brief
A security vulnerability has been identified in the Windows Kernel, the core component of the Microsoft Windows operating system. An authorized user with basic access to a system could exploit this flaw to gain full administrative control. This could allow an attacker to bypass security restrictions, access sensitive data, or disrupt business operations on affected workstations and servers.
Technical details
This vulnerability is classified as a use-after-free (CWE-416) within the Windows Kernel. An attacker must have local access and be authenticated with low privileges to exploit the flaw. By triggering the vulnerability, the attacker can execute code in kernel mode, leading to a full local privilege escalation (LPE) to SYSTEM. The issue affects multiple versions of Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this vulnerability.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
- 2026-07-14: advisory: Microsoft Security Response Center (MSRC) released an update guide.