Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.

Published 5 Sep 2026Updated 5 Sep 202610 sources
CVSS 8.8 ✓ VERIFIED REFERENCE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.