Executive brief
Windows Core Messaging is a fundamental system component that handles inter-process communication in Windows. A heap-based buffer overflow vulnerability in this component allows an authorized local attacker to execute arbitrary code with elevated privileges, potentially compromising system security and enabling full control of the affected computer.
Technical details
A heap-based buffer overflow exists in Windows Core Messaging that can be exploited by an authorized attacker to achieve privilege escalation on the local system. The vulnerability requires the attacker to have valid credentials and local access to trigger the overflow condition. Successful exploitation results in arbitrary code execution with elevated privileges. This is a local attack vector requiring prior authentication, mitigating external remote attack scenarios but remaining critical for insider threats or compromised account scenarios.
Affected products
- Microsoft Windows Core Messaging
Timeline
- 2026-09-08: disclosed