Executive brief
Windows COM (Component Object Model) is a core technology that allows different software components to communicate and interact on Windows systems. A use-after-free vulnerability in this component allows an authorized local user to execute code with elevated privileges, potentially gaining administrator access and compromising the entire system.
Technical details
A use-after-free vulnerability exists in Microsoft COM for Windows, where freed memory is accessed after deallocation. The vulnerability requires local access and prior authentication to exploit. An attacker with local user privileges can trigger the vulnerable code path to gain elevated (administrator) privileges on the affected Windows system. The vulnerability has not been exploited in the wild as of the advisory publication. Patches are available through Microsoft Security Response Center.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed