CVE-2026-73003
massUse-After-Free LPE in Windows Modern Device Management (MDM)
CVE-2026-73003 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component, rated High severity (CVSS 3.1: 7.0). An authorized attacker — a user with valid low-privileged local credentials — can trigger the bug via local actions, with high attack complexity and no user interaction required. Successful exploitation elevates the attacker's privileges on the local machine, with high impact to confidentiality, integrity, and availability, typically yielding administrator/SYSTEM-level access. Any Windows system carrying the Modern Device Management component is potentially affected, though specific affected Windows versions are not enumerated in the available data. There is no known public proof-of-concept, the flaw is not listed in CISA's KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days, so no exploitation is currently confirmed.
What to do: Apply Microsoft's security update for CVE-2026-73003 as it becomes available, prioritizing shared workstations, VDI hosts, kiosks, and other systems where low-privileged users have local logon rights. Until patched, restrict local and remote (RDP) logon to trusted accounts on Windows systems. Check Microsoft's advisory to confirm the exact affected Windows versions and fixed builds, since they are not specified in the available data.
| Microsoft Windows (Modern Device Management / MDM component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.