Microsoft Windows Internal System User Profile Privilege Escalation Vulnerability

Vulnerability

A use-after-free vulnerability has been identified in the Windows Internal System User Profile component. This vulnerability allows an authorized attacker to elevate privileges locally. It affects multiple versions of Windows 10 and Windows 11, as well as Windows Server 2025.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access within the system.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5099539 for Windows 10 and KB5101650 for Windows 11. For Windows Server 2025, the relevant update is also available through the Microsoft Update Catalog, with details in KB5099536.

Added: Jul 14, 2026, 11:40 PM
Updated: Jul 14, 2026, 11:40 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.