Microsoft Windows UI Automation Manager Privilege Escalation Vulnerability

Vulnerability

A race condition vulnerability has been identified in the UI Automation Manager (uiamanager.dll) of Microsoft Windows. This vulnerability allows an authorized attacker to elevate privileges locally by exploiting improper synchronization in concurrent execution using shared resources.

Impact

Successful exploitation of this vulnerability allows an attacker to elevate privileges from a low integrity level to a medium integrity level.

Remediation

Users can apply the security update KB5095051 to address this vulnerability. This security update is available through the Microsoft Update Catalog. For Windows Server 2025, the security update KB5094125 can be applied. For Windows Server 2022, the security update KB5094128 is available.

Added: Jun 9, 2026, 6:32 PM
Updated: Jun 9, 2026, 6:32 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
1.3
exploitability
2.9
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.