ZeroHour

CVE-2026-70577

mass

Use-After-Free Local Privilege Escalation in Windows Modern Device Management (MDM)

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-70577 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component, assigned directly by Microsoft. An attacker who already has valid low-privileged access on the local machine can trigger the flaw under specific conditions (attack complexity is rated high, with no user interaction required). Successful exploitation allows the attacker to elevate privileges locally, gaining high-impact read, write, and availability control on the affected system (C:H/I:H/A:H, CVSS 3.1 score 7.0). Anyone running Windows versions that include the Modern Device Management component is potentially affected, with the greatest risk on systems where untrusted or standard users can sign in locally. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% probability of exploitation within 30 days, indicating no confirmed in-the-wild exploitation to date.

What to do: Consult Microsoft's advisory for CVE-2026-70577 to identify the affected Windows builds and deploy the security update through Windows Update, WSUS, or Intune patch rings as it is released. Prioritize systems that permit untrusted or standard-user local logons (kiosks, shared workstations, VDI, and Entra/domain-joined endpoints), since the flaw requires local access and has high attack complexity. No PoC or in-the-wild exploitation is known, so standard patch cadence is reasonable while monitoring Microsoft advisories for updates.

Affected
Microsoft Windows Modern Device Management (MDM) component
Estimated exposure
masshundreds of millions to 1B+ Windows installations (the MDM component ships as part of Windows; local exploitation only) — The Modern Device Management component is part of the Windows operating system, so the potentially affected population scales with Microsoft's reported installed base of roughly 1.4 billion active Windows devices, though actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.