Untrusted Pointer Dereference in Microsoft Windows - CVE-2026-83939
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local privileged user to execute code in Virtual Trust Level 1 (VTL1).
The vulnerability exists due to untrusted pointer dereference in Windows Secure Kernel Mode when submitting a specially crafted Code Integrity policy to an affected system. A local privileged user can submit a specially crafted Code Integrity policy to execute code in Virtual Trust Level 1 (VTL1).