CVE-2026-69460
massUse-After-Free Privilege Escalation in Windows Modern Device Management (MDM)
CVE-2026-69460 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component assigned by Microsoft. Per the CVSS vector, a low-privileged authorized attacker could trigger the bug over a network with high attack complexity and some user interaction. Successful exploitation yields high-impact elevation of privilege on the target, with high confidentiality, integrity, and availability impact. Any Windows system carrying the in-box MDM/Modern Device Management component is in scope, though Microsoft's advisory is the authoritative source for affected versions. There is no public proof-of-concept, the flaw is not yet in CISA KEV, and EPSS puts 30-day exploitation probability at only about 0.5% (43rd percentile), so exploitation is not currently observed.
What to do: Patch as soon as Microsoft releases the security update addressing CVE-2026-69460 for the affected Windows versions listed in its advisory. In the interim, prioritize hosts where standard users interact with MDM enrollment or device-management flows, limit who can initiate MDM enrollment against your tenant, and monitor for unusual privilege-escalation activity on domain-joined and enrolled devices.
| Microsoft Windows Modern Device Management (MDM) component (shipped in-box with Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.