Executive brief
Windows Credential Providers contain a use-after-free vulnerability that allows an attacker with local access to elevate their privileges to a higher level on the system. This could enable an attacker to gain administrative control of a compromised computer, bypass security controls, and access sensitive data or perform unauthorized actions as a system administrator.
Technical details
A use-after-free memory corruption vulnerability exists in Windows Credential Providers, a core Windows component responsible for user authentication. The vulnerability can be triggered by an authorized local attacker through specific interactions with credential provider code, leading to memory corruption. An attacker with local access can exploit this flaw to achieve privilege escalation and execute arbitrary code with elevated privileges. A security update addressing this vulnerability is available from Microsoft.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed