ZeroHour

CVE-2026-72963

mass

Use-After-Free Local Privilege Escalation in Windows Modern Execution Server

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-72963 is a use-after-free vulnerability (CWE-416) in the Windows Modern Execution Server, a Microsoft Windows component, which Microsoft rated high severity (CVSS 7.0). An authorized attacker with low-level local access could trigger the flaw — exploiting freed memory, which typically involves a timing or race condition given the high attack complexity — to execute code in an elevated context. Successful exploitation would allow the local user to elevate privileges, gaining high-impact control over the confidentiality, integrity, and availability of the host. All Windows installations that include the affected Modern Execution Server component are exposed, though Microsoft has not specified affected version ranges in the available data. As of now there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns it only a 0.3% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-72963 through Windows Update as soon as it is released, and prioritize internet-reachable or multi-user endpoints where untrusted local accounts exist. Until patched, limit local logon rights to untrusted users and monitor Microsoft's advisory to confirm which Windows versions in your fleet are affected. No public proof-of-concept exists, but defenders should watch for updated KEV and EPSS signals given the component's ubiquity.

Affected
Microsoft Windows Modern Execution Server (Windows operating system component)
Estimated exposure
masslikely hundreds of millions to 1 billion+ Windows devices (built-in Windows component) — Modern Execution Server ships as part of the Windows operating system, whose install base exceeds a billion devices, so exposure plausibly spans the majority of Windows endpoints pending Microsoft's list of affected versions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.