Executive brief
Windows Defender Firewall Service is a core security component that manages network traffic filtering and protection on Windows systems. A heap-based buffer overflow vulnerability allows an authorized attacker with local access to escalate their privileges to system level, potentially compromising the entire computer and all data on it.
Technical details
A heap-based buffer overflow exists in the Windows Defender Firewall Service that can be triggered by an authorized local user. The vulnerability allows an attacker with authenticated local access to overflow a heap buffer in the firewall service, achieving code execution with elevated privileges. This is a local privilege escalation vulnerability requiring prior authentication and local code execution capability. Microsoft has issued patches to address this flaw. The CVSS base score is 7.0, reflecting the local-only attack vector but significant impact on system confidentiality and integrity.
Affected products
- Microsoft Windows Defender Firewall Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed