Executive brief
Windows Image Acquisition is a system component that enables applications to communicate with image capture devices such as scanners and cameras. A use-after-free vulnerability in this component allows an authorized local user to execute code with elevated system privileges, potentially leading to full system compromise or malware installation.
Technical details
A use-after-free vulnerability exists in Windows Image Acquisition, a system library component that handles interaction with imaging devices. The vulnerability allows an authenticated local attacker to trigger reuse of freed memory, resulting in arbitrary code execution with elevated privileges. This requires the attacker to already have local access to the system. Microsoft has released a security update to address this vulnerability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed