ZeroHour

CVE-2026-56177

mass

Use-after-free local privilege escalation in Microsoft Windows Server

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-56177 is a use-after-free memory-safety flaw (CWE-416) in Microsoft Windows Server that allows an authorized attacker to elevate privileges locally. A low-privileged user who can already execute code on the target server can trigger the flaw from a local session without user interaction (CVSS 3.1: AV:L/AC:L/PR:L/UI:N). Successful exploitation yields high confidentiality, integrity, and availability impact, granting the attacker elevated privileges on the host. All organizations running affected Windows Server versions are potentially in scope, though the specific affected builds are enumerated in Microsoft's advisory rather than in the available data. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, the CVE is not in CISA KEV, and EPSS assigns only a 0.3% probability of exploitation within 30 days (25th percentile).

What to do: Apply the Windows Server security update for CVE-2026-56177 from Microsoft's advisory at your next patching opportunity; no workaround or public exploit is currently known. Prioritize hosts where non-administrative or untrusted users hold local logon rights (e.g., RDS/session hosts, jump servers, shared build or test machines), since local elevation is most valuable to an attacker there. Factor this LPE into assessments of multi-vulnerability attack chains where it could follow a remote code execution flaw.

Affected
Microsoft Windows Server
Estimated exposure
masstens of millions of Windows Server instances worldwide (near-ubiquitous server OS); practical exposure limited to hosts granting local logon to… — Windows Server is one of the most widely deployed server operating systems across on-premises and cloud estates, giving an affected installed base in the tens of millions, though the local attack vector (AV:L) means only systems where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Server allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.