Executive brief
A flaw in the Windows Kernel allows an authorized user to escalate their privileges on a local system. An attacker with a user account could exploit this to gain administrative control, potentially enabling them to steal data, install malware, or compromise the entire system.
Technical details
The vulnerability is a privilege escalation issue caused by improper access control checks in the Windows Kernel. An authorized local user can exploit this flaw to elevate their privileges without additional user interaction. The attack requires the attacker to already have login credentials or local access to the system. Successful exploitation allows elevation from a standard user to a higher privilege level, potentially granting system-level access. A security patch from Microsoft is available to remediate this vulnerability.
Affected products
- Microsoft Windows Kernel
Timeline
- 2026-08-11: disclosed