CVE-2026-70577
massUse-After-Free Local Privilege Escalation in Windows Modern Device Management (MDM)
CVE-2026-70577 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component, assigned directly by Microsoft. An attacker who already has valid low-privileged access on the local machine can trigger the flaw under specific conditions (attack complexity is rated high, with no user interaction required). Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact read, write, and availability control on the affected system (C:H/I:H/A:H, CVSS 3.1 score 7.0). Anyone running Windows versions that include the Modern Device Management component is potentially affected, with the greatest risk on systems where untrusted or standard users can sign in locally. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation to date.
What to do: Consult Microsoft's advisory for CVE-2026-70577 to identify the affected Windows builds and deploy the security update through Windows Update, WSUS, or Intune patch rings as it is released. Prioritize systems that permit untrusted or standard-user local logons (kiosks, shared workstations, VDI, and Entra/domain-joined endpoints), since the flaw requires local access and has high attack complexity. No PoC or in-the-wild exploitation is known, so standard patch cadence is reasonable while monitoring Microsoft advisories for updates.
| Microsoft Windows Modern Device Management (MDM) component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.