ZeroHour

CVE-2026-73003

mass

Use-After-Free LPE in Windows Modern Device Management (MDM)

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-73003 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component, rated High severity (CVSS 3.1: 7.0). An authorized attacker — a user with valid low-privileged local credentials — can trigger the bug via local actions, with high attack complexity and no user interaction required. Successful exploitation elevates the attacker's privileges on the local machine, with high impact to confidentiality, integrity, and availability, typically yielding administrator/SYSTEM-level access. Any Windows system carrying the Modern Device Management component is potentially affected, though specific affected Windows versions are not enumerated in the available data. There is no known public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no exploitation is currently confirmed.

What to do: Apply Microsoft's security update for CVE-2026-73003 as it becomes available, prioritizing shared workstations, VDI hosts, kiosks, and other systems where low-privileged users have local logon rights. Until patched, restrict local and remote (RDP) logon to trusted accounts on Windows systems. Check Microsoft's advisory to confirm the exact affected Windows versions and fixed builds, since they are not specified in the available data.

Affected
Microsoft Windows (Modern Device Management / MDM component)
Estimated exposure
mass≈1 billion Windows devices (MDM component ships inbox with Windows 10/11) — Microsoft's Windows installed base exceeds roughly 1.4 billion devices and the Modern Device Management client is an inbox component of Windows 10/11, so the plausibly affected population is on the order of hundreds of millions to about a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.