Executive brief
Windows License Manager is a system component that handles software licensing on Windows machines. A use-after-free vulnerability in this component allows an authorized user to execute code with elevated privileges on the local system, potentially compromising the entire machine. This could enable attackers with user-level access to gain full administrative control.
Technical details
The vulnerability is a use-after-free flaw in Windows License Manager, a system service responsible for license validation and management. An authorized local attacker can trigger the use-after-free condition to gain privilege escalation on the affected system. The attack requires local access and authorization, limiting exposure to users already authenticated on the machine. A successful exploit allows the attacker to execute arbitrary code with SYSTEM privileges. Patches should be available through Microsoft's regular security update channels.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed