Executive brief
A security vulnerability exists in Microsoft Windows DirectX, a component responsible for handling graphical and multimedia tasks. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to install malicious software, view or delete sensitive data, or disrupt business operations.
Technical details
A use-after-free (CWE-416) vulnerability exists within the Windows DirectX component. The flaw is triggered when the system attempts to access memory that has already been deallocated, leading to memory corruption. To exploit this, an attacker must have local access to the target system with low-level user privileges. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue across various versions of Windows 10 and Windows 11.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft released security updates.