Executive brief
A security vulnerability exists in the Microsoft XML component of Windows that could allow an attacker with physical access to a device to bypass security protections. By exploiting how the system searches for files, an unauthorized person could potentially gain access to sensitive data or interfere with system operations. This risk is primarily relevant for lost or stolen devices where an attacker can interact directly with the hardware.
Technical details
An untrusted search path vulnerability (CWE-426) exists in Microsoft XML. The flaw allows an attacker with physical access to the target machine to bypass security features by placing a malicious file in a location that the system searches before legitimate directories. The attack requires high complexity, likely involving specific timing or environmental conditions during a physical interaction. If successful, the attacker can achieve high impact on confidentiality, integrity, and availability. Microsoft has released security updates for various Windows 10, 11, and Server 2012 versions to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard and Server Core
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2026-07-14: advisory: Microsoft Security Update Guide published.