Executive brief
A use-after-free vulnerability in Windows Shell allows an authorized attacker to elevate their privileges on a local system. An attacker with limited user account access could exploit this to gain administrative control of the affected computer, enabling complete system compromise including data theft, malware installation, or system destruction.
Technical details
A use-after-free vulnerability exists in the Windows Shell component, allowing privilege escalation from an authenticated user context to elevated privileges. The vulnerability requires local access and an authorized user account to exploit; successful exploitation could grant administrative privileges. The attack vector is local-only and does not affect remote attackers or unauthenticated users.
Affected products
- Microsoft Windows Shell
Timeline
- 2026-09-08: disclosed