Executive brief
A security vulnerability has been identified in the Windows Subsystem for Linux (WSL2), a tool that allows developers to run a Linux environment directly on Windows. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to unauthorized access to sensitive files, the installation of malicious software, or a complete takeover of the affected machine.
Technical details
A buffer over-read vulnerability (CWE-126) exists in Microsoft Windows Subsystem for Linux (WSL2). The flaw is triggered when the system improperly handles memory boundaries during specific operations, allowing an attacker to read data beyond the allocated buffer. An attacker with local access and low-level privileges can exploit this to execute code with elevated permissions, potentially gaining full SYSTEM access. The vulnerability affects WSL2 versions starting from 5.0.0.0 and is fixed in version 2.7.8. Exploitation requires local authentication but no user interaction.
Affected products
- Microsoft Windows Subsystem for Linux (WSL2) 5.0.0.0 to 2.7.7
Timeline
- 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.