Executive brief
A security vulnerability exists in the core of the Windows operating system that could allow a user who already has access to a computer to bypass certain security protections. While an attacker must already be able to log in to the system, this flaw could allow them to access information they are not supposed to see. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.
Technical details
An improper access control vulnerability (CWE-284) exists in the Windows Kernel. A locally authenticated attacker with low privileges can exploit this flaw to bypass security feature protections, potentially leading to unauthorized information disclosure. The attack requires local system access but no user interaction. Microsoft has addressed this vulnerability in the July 2026 security updates for affected versions of Windows 10, Windows 11, and Windows Server 2012.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard and Server Core
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory