# CVE-2026-62892 — Windows Capability Access Management Service (camsvc) `capabilityaccessmanager.dll` Consent-Object Race → Use-After-Free

---

## Summary

| | |
|---|---|
| **Product** | Windows — `capabilityaccessmanager.dll` (Capability Access Management Service / camsvc, runs as SYSTEM) |
| **CVE ID** | CVE-2026-62892 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.0 / 6.1 — `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-416: Use After Free (race-triggered) |
| **Delivery** | Local — concurrent capability consent operations (race) |
| **KB / Fixed build** | KB5121003 — `capabilityaccessmanager.dll` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `capabilityaccessmanager.dll` 10.0.26100.8972 — SHA256 `6ce99af4766b4416d0b4bc544455c99289c50f65d3d477a4b590b066b519094b` |
| **Post-patch binary** | `capabilityaccessmanager.dll` 10.0.26100.9168 — SHA256 `53ecf43f987d74cd54e5b36c79f3a3c02dbc66da6cd6a7cdd91da20de3a2c328` |
| **Feature flag** | `Feature_1944813881` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`capabilityaccessmanager.dll` implements the **Capability Access Management Service**
(camsvc), which mediates app access to protected capabilities (camera, microphone,
location) and their consent state. Access is evaluated in
`CapabilityAccessManager::EvaluateGlobalPrompt` / `ConsentCheck`, which read consent
via the per-user `CapabilityConsentManager` (`GetUserGlobalConsent` /
`GetUserAppConsent`, off the manager stored at `this + 0x60`).

---

## Vulnerability Summary

Pre-patch, the consent objects used during evaluation were held via **raw pointers**.
A concurrent operation (a consent change or teardown) could therefore free the
consent / manager object while another thread was still using it inside the
evaluation — a use-after-free (CWE-416), triggered by winning the race (`AC:H`).
Because camsvc runs as **SYSTEM** and the consent interface is reachable by a local
user, the freed-object reuse is a local elevation-of-privilege primitive to SYSTEM
(per the MSRC FAQ).

> Confirmation level: this August update is a **broad camsvc rework** (99 functions
> modified across many feature flags). The isolable UAF mechanism is the change to
> **reference-counted (`std::shared_ptr`) ownership** of the consent object in the
> `EvaluateGlobalPrompt` / `ConsentCheck` path, gated behind the dominant flag
> `Feature_1944813881`; it is stated here at confirmed-changed level.

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`); `AC:H` — must win a race between a consent
  change/teardown and an in-flight access evaluation.
- Result: a freed consent/manager object is used during evaluation.

---

## Vulnerability Details

### Root Cause

The consent object was referenced by raw pointer during access evaluation, with no
strong reference held, so a concurrent free could invalidate it mid-use.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_1944813881`, the consent accessors now return/hold the consent
via **`std::shared_ptr<CapabilityConsentManager>`** with reference-count management
(`_Ref_count_base`), so a strong reference is held across the evaluation:

```c
// CapabilityAccessManager::EvaluateGlobalPrompt (10.0.26100.9168) — PATCHED (from the diff)
if (Feature_1944813881__private_IsEnabled()) {
    get_TargetObjectId(this);
    CapabilityConsentManager::GetConsentIdFromObjectId(...);
    // consent accessor now yields a shared_ptr (strong ref), assigned via operator=:
    psVar19 = CapabilityConsentManager::GetUserGlobalConsent(*(CapabilityConsentManager**)(this+0x60), ...);
    shared_ptr<...CapabilityConsentManager>::operator=(&local, psVar19);   // strong ref held
    if (local_610 != NULL) { /* _Ref_count_base decref of prior */ }
    // ... GetUserAppConsent(...) similarly held via shared_ptr ...
}
```

Holding a `shared_ptr` (reference-counted) to the consent object across the
evaluation keeps it alive while in use, so a concurrent operation can no longer free
it mid-evaluation, closing the race/UAF.

### Patch Completeness Assessment

**CFR-gated behind `Feature_1944813881`.** The reference-counted consent lifetime runs
only when the flag is enabled; the original raw-pointer path still ships when
disabled. Verify `Feature_1944813881` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Rapid/concurrent capability consent changes racing access
evaluations; use-after-free / heap-corruption bugchecks in
`capabilityaccessmanager!...CapabilityAccessManager::EvaluateGlobalPrompt` /
`ConsentCheck` within the SYSTEM camsvc on unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_1944813881` is enabled.

---

## References

- MSRC advisory — CVE-2026-62892 (Capability Access Management Service (camsvc) Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/capabilityaccessmanager_dll-cve-2026-62892-ghidriff.md`
