We'd like to thank @AretiqAI for sharing their analysis and proof of concept, which allowed us to create patches for Windows versions that are no longer receiving official updates from Microsoft.
We'd like to thank TrustedSec researcher Christopher Paschen (@freefirex2) for sharing the details and their proof-of-concept, which allowed us to create a patch for Windows users who are no longer receiving official Windows patches.
We'd like to thank Google Project Zero security researcher James Forshaw (https://t.co/d8IwevR7sN) and MDSec's Filip Dragovic (@filip_dragovic) for publishing their analyses and proofs-of-concept, which allowed us to create a patch for legacy Windows users.
Micropatches released for Windows Accessibility Infrastructure Elevation of Privilege Vulnerability (CVE-2026-24291, CVE-2026-25186, CVE-2026-25187) https://t.co/dabuY7TV06
We'd like to thank Sergey Bliznyuk (@justbronzebee ) with Positive Technologies for sharing their detailed article, which allowed us to create patches for Windows versions that are no longer receiving official updates from Microsoft.
We'd like to thank Denis Faiustov and Ruslan Sayfiev with GMO Cybersecurity by Ierae for finding this vulnerability, and Clément Labro (@itm4n) for publishing their analysis and proof-of-concept, which allowed us to create a patch for legacy Windows users.
We'd like to thank Oscar Zanotti Campo (https://t.co/nyrkEx3AYv) for sharing their analysis and proof-of-concept, which allowed us to create a patch and protect 0patch users against this issue.
We'd like to thank Tianlin Zhang (@T0Zhang) for discovering this vulnerability and Clément Labro (https://t.co/g9zU5JYYjJ) for publishing their analysis, both of which allowed us to create a patch and protect 0patch users against this issue.
We'd like to thank SSD Secure Disclosure (@SecuriTeam_SSD) for discovering this vulnerability and publishing their analysis, which allowed us to create a patch and protect 0patch users against this issue.
We'd like to thank Alberto Bruscino (@ErPaciocco) for sharing vulnerability details and POC, which allowed us to create a patch for this issue and protect our users.
Patches were written for:
- Microsoft Office 2016 and 2019 click-to-run with all available updates (version 2508, build 19127.20302)
- Microsoft Office 2010 and 2013 with all available updates
Office 2016 and 2019 volume license received an official patch from Microsoft.