# CVE-2026-61357 — Windows Application Information Service `appinfo.dll` Use-After-Free in `RAiLaunchAdminProcess` (UAC Elevation Broker) → EoP to SYSTEM

---

## Summary

| | |
|---|---|
| **Product** | Windows — `appinfo.dll` (Application Information Service / AppInfo; UAC elevation broker) |
| **CVE ID** | CVE-2026-61357 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.8 / 6.8 — `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-416: Use After Free |
| **Delivery** | Local — a call to the AppInfo RPC method `RAiLaunchAdminProcess` |
| **KB / Fixed build** | KB5121003 — `appinfo.dll` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `appinfo.dll` 10.0.26100.8972 — SHA256 `ef6a0081feb04b1daa751907d085895c733a5a095fea8c593afbb6db6ba5065e` |
| **Post-patch binary** | `appinfo.dll` 10.0.26100.9168 — SHA256 `2f1a7547b89019bf9bbbf2685ee598945c1ed9e280106739545755efcd5b4d94` |
| **Feature flag** | `Feature_1715195192` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`appinfo.dll` implements the **Application Information Service** (AppInfo), the
SYSTEM service behind User Account Control. When a user runs a program elevated
(ShellExecute `runas`, the consent prompt, etc.), the client calls the AppInfo RPC
method **`RAiLaunchAdminProcess`**, which validates the request, impersonates the
calling client (`RpcImpersonateClient`), builds the launch parameters, and starts
the elevated process, reverting impersonation (`RpcRevertToSelf`) around the
sensitive steps. Its parameters include the application path, command line, and
startup info; several are heap-allocated `LocalFree`-owned `WCHAR` buffers.

---

## Vulnerability Summary

Inside `RAiLaunchAdminProcess`, one of the heap-allocated request buffers was
**freed while a stale pointer to it was still used** on a later step or error path
— a use-after-free of a `LocalFree`'d buffer (CWE-416). The method is reachable by
an unprivileged local caller of the AppInfo RPC interface, and because AppInfo runs
as **SYSTEM** and performs the elevated launch, controlling the freed-then-reused
allocation is a local elevation-of-privilege primitive that yields SYSTEM (per the
MSRC FAQ, successful exploitation gains SYSTEM).

The pre/post diff confirms `RAiLaunchAdminProcess` is code-changed under
`Feature_1715195192`, with the fix introducing a `wil::unique_any_t` RAII string
guard (below). The exact freed local variable is not cleanly isolable in this large
refactor, so the specific buffer is stated at confirmed-changed level; the mechanism
follows the CWE-416 classification and the RAII-guard evidence.

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`, `AC:L`): invoke the AppInfo RPC
  `RAiLaunchAdminProcess` (the same interface the `runas`/consent path uses).
- Drive the request so the vulnerable heap buffer is freed and then referenced
  again on the subsequent/error path.
- Result: use-after-free inside the SYSTEM AppInfo service.

---

## Vulnerability Details

### Root Cause

A `LocalFree`-owned request buffer in `RAiLaunchAdminProcess` had a lifetime that
was not bound to its single owner: it was freed, but a raw pointer to it was still
used afterward (on a later step or an error/cleanup path), producing a
use-after-free in the SYSTEM elevation broker.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_1715195192`, `RAiLaunchAdminProcess` is reworked to manage the
affected buffer through a **`wil::unique_any_t` RAII wrapper with a `LocalFree`
resource policy** (allocated via `make_unique_string_nothrow`, assigned/reset via
the wrapper, destroyed at scope exit), so the buffer is freed exactly once and can
no longer be referenced after free. The `RpcImpersonateClient` / `RpcRevertToSelf`
sequence around the affected code is restructured at the same time:

```c
// RAiLaunchAdminProcess (10.0.26100.9168) — PATCHED, feature-enabled branch (from our diff)
if (wil::Feature<Feature_1715195192>::__private_IsEnabled()) {
    // buffer now owned by a scoped RAII guard (LocalFree resource policy):
    wil::unique_any_t<...LocalFree...> guard;
    wil::make_unique_string_nothrow(guard, ...);   // allocate + own
    // ... use guard.get() ...; guard released exactly once at scope exit
}
```

By binding the buffer to `unique_any_t`, the free happens once at a well-defined
point and no stale raw pointer survives, closing the use-after-free.

### Patch Completeness Assessment

**CFR-gated behind `Feature_1715195192`.** The RAII-managed lifetime runs only when
the flag is enabled; the original use-after-free path still ships when disabled.
Verify `Feature_1715195192` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Anomalous or malformed calls to the AppInfo RPC
`RAiLaunchAdminProcess` (elevation requests) from unprivileged processes,
especially patterns that drive error/cleanup paths repeatedly; use-after-free /
heap-corruption crashes in `appinfo!RAiLaunchAdminProcess` within the SYSTEM
Application Information Service on unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_1715195192` is enabled.

---

## References

- MSRC advisory — CVE-2026-61357 (Application Information Services Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/appinfo_dll-cve-2026-61357-ghidriff.md`
