Executive brief
Windows Security Health Service is a system component that monitors and reports the health status of Windows security features. A use-after-free memory corruption vulnerability allows an authenticated local attacker to execute arbitrary code with elevated privileges, potentially leading to full system compromise or malware installation.
Technical details
The vulnerability is a use-after-free (UAF) in Windows Security Health Service, a memory corruption flaw where the service attempts to access memory that has already been freed. This occurs in a component accessible to authenticated local users. An attacker with local access and valid credentials can trigger the vulnerability through a specific sequence of operations, allowing execution of arbitrary code in the context of the elevated service. Microsoft has released a patch; consult the MSRC advisory for patch availability and affected Windows versions.
Affected products
- Microsoft Windows Security Health Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory