Executive brief
Windows Remote Access API contains a heap-based buffer overflow vulnerability that allows an authorized local attacker to elevate privileges on affected systems. Exploitation could lead to system compromise and unauthorized access to sensitive data or critical operations.
Technical details
A heap-based buffer overflow exists in the Windows Remote Access API, exploitable by an authenticated attacker with local access. The vulnerability allows an attacker to overwrite heap memory and achieve privilege escalation from a lower-privileged account to a higher-privileged context. Attack preconditions include local system access and valid credentials. Microsoft has released patches to address this vulnerability. The root cause involves improper bounds checking in memory allocation routines within the Remote Access subsystem.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-08-11: disclosed