Executive brief
Windows Connected User Experiences and Telemetry is a system service that manages user data and device telemetry in Windows. A use-after-free vulnerability in this service allows an authorized local user to escalate privileges and gain administrative control of the system, potentially enabling malware installation or system compromise.
Technical details
The vulnerability is a use-after-free memory corruption flaw in the Windows Connected User Experiences and Telemetry service. An authenticated local attacker with standard user privileges can trigger the memory corruption to escalate to SYSTEM-level privileges. The attack requires local access and authenticated credentials, making it suitable for lateral movement or privilege escalation in multi-user environments. A patch is expected from Microsoft's security update process.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed