CVE-2026-73005
massUse-after-free local privilege escalation in Microsoft Windows Authentication Methods
CVE-2026-73005 is a use-after-free (CWE-416) arising from a race condition (CWE-362) in the Windows Authentication Methods component of Microsoft Windows. A local attacker who is already authorized on the machine (low-privileged account, no user interaction required) must win a timing race that frees memory still in use by authentication routines. Successful exploitation lets the attacker elevate privileges locally, gaining high impact on confidentiality, integrity, and availability of the host. Any organization or individual running Windows with local user accounts is in scope, though exploitation requires pre-existing local access. As of now there is no public proof-of-concept, it is not listed in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.
What to do: Track Microsoft's advisory for this CVE and apply the security update to affected Windows releases as soon as it is available for your servicing channel. In the interim, restrict local interactive and remote logon rights to trusted accounts and monitor for any newly published PoCs or in-the-wild reports. Given the local attack vector, hard-to-trigger race condition (CVSS AC:H), and low EPSS, this can be handled on a normal patching cadence but should not be deferred beyond your next cycle.
| Microsoft Windows Authentication Methods (Windows OS authentication component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.