CVE-2026-61357 — Application Information Services Elevation of Privilege Vulnerability
Executive Summary
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5121000 |
Security Update | Yes |
Patch Diff
Use-after-free (CWE-416) in the Windows Application Information Service (AppInfo / UAC elevation broker) appinfo.dll RAiLaunchAdminProcess, local EoP to SYSTEM. RAiLaunchAdminProcess is the RPC method a client invokes to request launch of an elevated (admin) process (the AppInfo interface behind ShellExecute 'runas' / consent). It impersonates the calling client (RpcImpersonateClient), builds several heap-allocated request strings/parameters (application path, parameters, etc.; LocalFree-owned WCHAR buffers), and drives the elevated launch, reverting impersonation (RpcRevertToSelf) around the sensitive steps. PRE: one of these heap allocations was freed but a stale pointer to it was still used on a later step / error path (a use-after-free of a LocalFree'd buffer), reachable by an unprivileged local caller of the AppInfo RPC and, because AppInfo runs as SYSTEM and performs the launch, exploitable for local EoP to SYSTEM. Diff of appinfo.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_1715195192, RAiLaunchAdminProcess is reworked to manage the affected string via a wil::unique_any_t RAII wrapper (make_unique_string_nothrow with a LocalFree resource policy; assignment/reset/scoped-destruction), binding the buffer's lifetime so it is freed exactly once and cannot be referenced after free, and the RpcImpersonateClient/RpcRevertToSelf sequence around it is restructured. Note: RAiLaunchAdminProcess is confirmed code-changed under Feature_1715195192 with the new RAII string guard; the exact freed local is not cleanly isolable in this large refactor, so the precise freed buffer is stated at confirmed-changed level and the mechanism follows the CWE-416 classification and the RAII-guard evidence.
| Function | Address | Change | Note |
|---|---|---|---|
RAiLaunchAdminProcess |
code change |
code (affected buffer now RAII-managed; impersonation flow restructured, CFR-gated) | Pre: a LocalFree-owned WCHAR request buffer was freed but a stale pointer was still used on a later/error path -> UAF, reachable by the unprivileged AppInfo RPC client. Post (Feature_1715195192): the buffer is held in wil::unique_any_t<...LocalFree...> (make_unique_string_nothrow / operator= / reset), so it is freed once and never used after free; RpcImpersonateClient/RpcRevertToSelf ordering reworked. |
LUATelemetry::LaunchAdminProcess |
code change |
code (telemetry helper extracted/updated) | Templated telemetry helper around the admin-launch path, updated alongside RAiLaunchAdminProcess under the same gate. |
Feature_1715195192 |
gate |
added (CFR gate) | CFR flag gating the RAII-managed lifetime fix; the original use-after-free path still ships when disabled. |
Attack Path
An unprivileged client's elevation RPC frees a request buffer that AppInfo then uses after free, in the SYSTEM elevation broker
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Brandon Fisher
Pwnforr777