ZeroHour

CVE-2026-69460

mass

Use-After-Free Privilege Escalation in Windows Modern Device Management (MDM)

CVSS 3.1
7.1 high
EPSS
<1%p43
Published
()
Modified
AI analysis

CVE-2026-69460 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component assigned by Microsoft. Per the CVSS vector, a low-privileged authorized attacker could trigger the bug over a network with high attack complexity and some user interaction. Successful exploitation yields high-impact elevation of privilege on the target, with high confidentiality, integrity, and availability impact. Any Windows system carrying the in-box MDM/Modern Device Management component is in scope, though Microsoft's advisory is the authoritative source for affected versions. There is no public proof-of-concept, the flaw is not yet in CISA KEV, and EPSS puts 30-day exploitation probability at only about 0.5% (43rd percentile), so exploitation is not currently observed.

What to do: Patch as soon as Microsoft releases the security update addressing CVE-2026-69460 for the affected Windows versions listed in its advisory. In the interim, prioritize hosts where standard users interact with MDM enrollment or device-management flows, limit who can initiate MDM enrollment against your tenant, and monitor for unusual privilege-escalation activity on domain-joined and enrolled devices.

Affected
Microsoft Windows Modern Device Management (MDM) component (shipped in-box with Windows)
Estimated exposure
massroughly hundreds of millions to ~1.4 billion Windows endpoints (Microsoft's reported active Windows install base) — The MDM/Modern Device Management client ships in-box with Windows, so exposure approximates the overall Windows device base (~1.4 billion active devices per Microsoft), though practical exploitability depends on enrollment state, local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.