Executive brief
Windows Power Dependency Coordinator is a system component that manages power and dependency relationships for services and processes on Windows systems. A heap-based buffer overflow in this component allows authenticated local users to execute arbitrary code and elevate their privileges to administrative level, potentially compromising system security.
Technical details
This vulnerability is a heap-based buffer overflow in the Windows Power Dependency Coordinator component. The vulnerability can be exploited by an authorized/authenticated local attacker to trigger a buffer overflow condition, leading to arbitrary code execution with elevated privileges. The attack vector is local, requiring prior authentication or local system access. A patch has been published by Microsoft through their Security Update Guide.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed