Executive brief
Windows Display Enhancement Service is a system component that manages display settings and visual features. A double free memory vulnerability in this service allows an authorized local attacker to crash the service or execute arbitrary code with elevated system privileges, potentially compromising the entire Windows system.
Technical details
A double free vulnerability exists in the Windows Display Enhancement Service, allowing an authenticated local attacker to trigger the same memory region being freed twice during processing. This memory corruption condition can lead to heap corruption and code execution at the privilege level of the affected service. The vulnerability requires local access and an authorized user account to trigger. Exploitation could allow an attacker to escalate privileges from a standard user to SYSTEM or administrator level. Microsoft has released a security patch addressing this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed