Executive brief
The Data Sharing Service Client, a Windows component used for sharing data between applications, contains an authorization flaw that allows an already-authenticated user to gain elevated privileges on their local system. An attacker with valid user credentials could exploit this to gain administrative access and compromise the integrity of the system.
Technical details
The vulnerability is a missing authorization check in the Data Sharing Service Client that fails to properly validate privilege levels before performing sensitive operations. The flaw requires local access and an existing user account to exploit, allowing privilege escalation from a standard user to elevated system privileges. An authenticated local attacker can bypass authorization controls to perform actions requiring higher privileges. A patch from Microsoft addressing this authorization validation is available and should be applied promptly.
Affected products
- Microsoft Data Sharing Service Client
Timeline
- 2026-09-08: disclosed