Executive brief
Windows Overlay Filter is a system component that manages visual overlays in Windows. A heap-based buffer overflow in this component allows an authorized user to execute arbitrary code with elevated privileges, potentially leading to full system compromise.
Technical details
A heap-based buffer overflow vulnerability exists in Windows Overlay Filter that can be exploited by an authorized local user to execute arbitrary code. The vulnerability requires the attacker to have prior local access and execute a specially crafted input to overflow a heap buffer in the filter. Successful exploitation allows privilege escalation to a higher privilege level. A patch from Microsoft is available.
Affected products
- Microsoft Windows Overlay Filter
Timeline
- 2026-09-08: disclosed