Executive brief
Windows Virtual Trusted Platform Module (vTPM) is a security component that manages cryptographic keys and protects sensitive system operations. A use-after-free vulnerability in this component allows an authorized local user to escalate their privileges to a higher privilege level, potentially gaining full system control.
Technical details
A use-after-free vulnerability exists in Windows Virtual Trusted Platform Module, where freed memory is accessed after deallocation, leading to memory corruption. The vulnerability requires that an attacker already has local authentication/authorization on the target system. The attack vector is local, meaning the attacker must execute code with user-level privileges on the affected machine. Successful exploitation allows privilege escalation from an authorized user account to a higher privilege level. Patches are available from Microsoft Security Response Center.
Affected products
- Microsoft Windows Virtual Trusted Platform Module
Timeline
- 2026-09-08: disclosed