Executive brief
Windows Smart Card is a system component used for secure authentication and certificate management on Windows systems. An authorized attacker can exploit an untrusted search path vulnerability to escalate privileges on a local machine, potentially gaining full system control.
Technical details
This vulnerability exists in Windows Smart Card due to an untrusted search path that can be exploited during library/module loading. An attacker with local access can leverage this to achieve privilege escalation through DLL hijacking or similar path-based attack techniques. The vulnerability requires the attacker to be already authenticated or authorized on the system. The impact allows elevation from a standard or local user context to higher privileges, potentially reaching SYSTEM level. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Smart Card
Timeline
- 2026-09-08: disclosed