Executive brief
A flaw in Windows Kernel Mode Driver allows an authorized local user to trigger an integer underflow condition, which can be exploited to gain elevated system privileges. This impacts the security boundary of Windows systems, potentially allowing attackers with user-level access to take complete control of a compromised machine.
Technical details
The vulnerability is an integer underflow (wraparound) condition in the Windows Kernel Mode Driver. The flaw requires an authenticated attacker with local access to trigger the vulnerable code path. By exploiting the integer underflow, an attacker can manipulate kernel memory or execution flow to escalate their privileges from user mode to kernel mode. The attack vector is local and requires prior system access; no network exploitation is possible. Microsoft has issued a security patch to address this vulnerability.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed