CVE-2026-56177
massUse-after-free local privilege escalation in Microsoft Windows Server
CVE-2026-56177 is a use-after-free memory-safety flaw (CWE-416) in Microsoft Windows Server that allows an authorized attacker to elevate privileges locally. A low-privileged user who can already execute code on the target server can trigger the flaw from a local session without user interaction (CVSS 3.1: AV:L/AC:L/PR:L/UI:N). Successful exploitation yields high confidentiality, integrity, and availability impact, granting the attacker elevated privileges on the host. All organizations running affected Windows Server versions are potentially in scope, though the specific affected builds are enumerated in Microsoft's advisory rather than in the available data. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile).
What to do: Apply the Windows Server security update for CVE-2026-56177 from Microsoft's advisory at your next patching opportunity; no workaround or public exploit is currently known. Prioritize hosts where non-administrative or untrusted users hold local logon rights (e.g., RDS/session hosts, jump servers, shared build or test machines), since local elevation is most valuable to an attacker there. Factor this LPE into assessments of multi-vulnerability attack chains where it could follow a remote code execution flaw.
| Microsoft Windows Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Server allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.