Executive brief
Windows Secure Kernel Mode is a core Windows security component that protects sensitive operations. An integer overflow vulnerability in this component allows an authorized attacker with local system access to bypass security controls and gain elevated privileges, potentially compromising the entire system.
Technical details
An integer overflow or wraparound vulnerability exists in Windows Secure Kernel Mode. The vulnerability can be exploited by an authorized attacker with local access to elevate privileges. The attack requires prior system access but does not require network connectivity. Successful exploitation allows an attacker to escalate from a limited user context to higher privilege levels, potentially gaining system-level control. A patch from Microsoft is expected to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed