CVE-2026-70567
massDouble Free Local Privilege Escalation in Windows Display Enhancement Service
CVE-2026-70567 is a double-free memory corruption flaw (CWE-415) in the Windows Display Enhancement Service, a local Windows component. An attacker who already holds limited privileges on the machine can trigger the service to release the same memory allocation twice; the high attack complexity indicates specific conditions are needed, but no user interaction is required. Successful exploitation lets the attacker elevate privileges locally, with high impact on confidentiality, integrity, and availability on the compromised system (CVSS 3.1: 7.0, high). Any Windows system running the affected service is potentially exposed, though the affected version ranges are not specified in the available data. There is currently no known public proof-of-concept, no CISA KEV listing, and a low 0.3% EPSS probability of exploitation within 30 days, so no exploitation is known.
What to do: Apply the Microsoft security update for this CVE via Windows Update as soon as it is available, and check Microsoft's advisory for the definitive list of affected Windows versions, since the available data does not specify them. Because exploitation requires local access, prioritize systems where untrusted or low-privileged users can sign in, such as shared workstations, kiosks, and Remote Desktop/Terminal Servers. No public PoC, workaround, or observed exploitation is known, so routine patch-cadence handling is currently reasonable.
| Microsoft Windows (Display Enhancement Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.