Google Project Zero published records for two Windows privilege-escalation issues affecting core operating system behavior. One issue describes a Windows kernel flaw in which a registry security descriptor reference count can overflow when it is referenced by too many transacted operations, a condition that could enable elevation of privilege in the kernel. A separate Project Zero bug record identifies a Windows issue involving system drive replacement during impersonation, also categorized as an elevation-of-privilege flaw.
The available references provide only limited technical and remediation detail, but they indicate that both findings were tracked through Project Zero's vulnerability disclosure process and affect Microsoft Windows security boundaries. For defenders, the disclosures highlight risk around low-level Windows components tied to the registry, transaction handling, and impersonation logic, and they warrant validation that relevant Microsoft fixes for the associated Project Zero-reported issues have been applied across supported Windows systems.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A Project Zero issue record was published for a Windows kernel vulnerability described as "registry security descriptor refcount may overflow when referenced by too many transacted operations." The visible metadata indicates a vulnerability record exists, but the excerpt does not expose the CVE, vendor, fix status, or full technical details.
Google Project Zero published issue 2451 titled "Windows: System Drive Replacement During Impersonation EoP" in its bug tracker. The provided reference does not include further technical details or remediation information.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
project-zero.issues.chromium.org
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.