Executive brief
A use-after-free vulnerability in the Windows Kernel allows an authorized attacker with network access to elevate their privileges to a higher level on affected systems. This could enable an attacker to gain administrative control, compromise system integrity, and potentially move laterally within an organization's network.
Technical details
A use-after-free vulnerability exists in the Windows Kernel that permits privilege escalation. The vulnerability requires an authorized attacker with network access to exploit. An attacker can trigger the use-after-free condition to elevate privileges beyond their current authorization level. This vulnerability carries a CVSS score of 7.1 and has not been observed in active exploitation at this time. Patches are available from Microsoft via their Security Update Guide.
Affected products
- Microsoft Windows Kernel <UNKNOWN>
Timeline
- 2026-09-08: disclosed