Executive brief
Windows Management Instrumentation (WMI), a core system service for managing Windows infrastructure, contains a use-after-free vulnerability that allows authorized network users to escalate their privileges. An attacker with valid credentials could exploit this flaw to gain elevated system access, potentially compromising entire systems or gaining administrative control.
Technical details
A use-after-free vulnerability exists in the Windows Management Instrumentation service, allowing an authenticated remote attacker to elevate privileges via network access. The vulnerability requires the attacker to already have legitimate credentials to initiate a WMI connection, but once exploited grants elevated system-level permissions without additional user interaction.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed