Executive brief
The Windows Program Compatibility Assistant Service is a system component that helps applications run with compatibility settings. A heap buffer overflow vulnerability in this service allows an authorized attacker to execute arbitrary code and escalate their privileges to system level, potentially compromising the entire computer.
Technical details
A heap-based buffer overflow exists in the Windows Program Compatibility Assistant Service that can be triggered by an authorized attacker. The vulnerability allows an attacker with local access to craft malicious input that overflows a heap buffer, leading to memory corruption and code execution. By exploiting this flaw, an attacker can achieve privilege escalation from their current user context to SYSTEM level. The vulnerability requires local authentication and user interaction or specific conditions to trigger the overflow. A patch is available from Microsoft through their Security Update Guide.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed