Executive brief
Windows Image Acquisition is a Windows system component that handles image file processing and acquisition. A use-after-free memory vulnerability in this component allows an authorized local user to elevate their privileges to a higher level of system access, potentially gaining administrative control.
Technical details
The vulnerability is a use-after-free condition in the Windows Image Acquisition component. The flaw can be triggered by an authorized local attacker through local access. Exploitation requires prior authentication and local system access; however, successful exploitation allows privilege escalation to a higher privilege level on the affected system. A patch is expected to be available from Microsoft through their regular security updates.
Affected products
- Microsoft Windows Image Acquisition
Timeline
- 2026-09-08: disclosed