Executive brief
Windows Group Policy, a system used to apply security policies and configurations across corporate networks, contains a vulnerability that allows an authorized attacker to execute code with elevated privileges by sending a specially crafted network request. Exploitation could allow an attacker to take control of affected systems and access sensitive corporate data or disrupt business operations.
Technical details
The vulnerability is a untrusted pointer dereference in Windows Group Policy that permits privilege escalation. An authorized attacker can exploit this over the network by sending a malicious request that causes the Group Policy service to dereference a pointer under attacker control. Exploitation requires network access and prior authentication. A successful exploit grants the attacker elevated privileges, potentially enabling full system compromise.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed