CVE-2026-72958
massDouble Free in Windows Credential Guard Enables Local Privilege Escalation
Windows Credential Guard contains a double-free memory corruption flaw (CWE-415), in which the same memory allocation is released twice, corrupting memory within the isolated, virtualization-based security component. An authorized attacker who already holds high privileges on the local system can trigger the condition to elevate privileges, with high impact on confidentiality, integrity, and availability beyond the component's security scope (as reflected in the changed scope in the CVSS vector). Successful exploitation undermines Credential Guard's isolated credential protection, allowing an attacker to gain greater rights on the affected host than their existing elevated access should permit. Any Windows deployment with Credential Guard enabled is in scope, though exploitation requires pre-existing high local privileges and no user interaction. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for this CVE as soon as it is available for your Windows editions (no fixed version numbers are provided in the source data, so track Microsoft's advisory for the exact update). Because exploitation requires an attacker to already have high local privileges, prioritize patching servers and workstations where multiple administrators or privileged services operate, and restrict local admin rights as a compensating control. You can confirm whether Credential Guard is running on an endpoint by checking the Win32_DeviceGuard WMI class (SecurityServicesRunning) or System Information (msinfo32) before deciding urgency.
| Microsoft Windows Credential Guard | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.