Executive brief
Windows Modern Execution Server is a core Windows component that manages application execution and process lifecycle. A use-after-free vulnerability allows an authenticated local attacker to escalate privileges, potentially gaining full control of the compromised system.
Technical details
A use-after-free vulnerability exists in Windows Modern Execution Server that permits a local, authenticated attacker to execute arbitrary code with elevated privileges. The vulnerability requires prior authentication and local access to the affected system. Successful exploitation results in privilege escalation to a higher privilege level, potentially system/administrative context. Microsoft has issued security updates to remediate this issue.
Affected products
- Microsoft Windows Modern Execution Server
Timeline
- 2026-09-08: disclosed