Executive brief
A flaw in Windows Error Reporting allows an authenticated attacker to cause a heap-based buffer overflow and gain elevated privileges on an affected system. This could enable an attacker with local access to take complete control of a Windows machine, potentially leading to data theft or malware installation.
Technical details
A heap-based buffer overflow exists in Windows Error Reporting that can be triggered by an authenticated local attacker without user interaction. The vulnerability allows memory corruption that enables privilege escalation from standard user to SYSTEM or administrator level. A patch is available from Microsoft.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed