Executive brief
Windows Core Messaging is a system component responsible for handling inter-process communication on Windows systems. A type confusion vulnerability in this component allows an authorized attacker with local access to escalate their privileges to a higher level, potentially gaining administrative control of the system and its data.
Technical details
This vulnerability is a type confusion flaw in Windows Core Messaging, where an attacker can access resources using an incompatible type, leading to memory corruption. The vulnerability requires the attacker to be authorized on the system and have local access. By exploiting this type confusion, an authenticated local attacker can elevate their privileges and execute arbitrary code with higher privileges. A security patch has been released by Microsoft to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed