CVE-2026-73012
massHeap Buffer Overflow in Windows Management Services Enables Network Privilege Escalation
CVE-2026-73012 is a heap-based buffer overflow (CWE-122) in Windows Management Services, a networking component maintained by Microsoft. An authorized attacker who already holds valid low-privileged credentials can send specially crafted requests to the affected service over the network, with no user interaction required. Successful exploitation lets the attacker elevate privileges on the target host, and the 8.8 CVSS score indicates high impact to confidentiality, integrity, and availability of the compromised system. Windows deployments running the affected service are at risk, primarily on internal networks or remotely reachable hosts where attackers can authenticate and reach the service; no specific affected version ranges are provided in the available data. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS assigns only a 0.6% chance of exploitation within 30 days, so no confirmed in-the-wild exploitation is known.
What to do: Apply the Windows security update addressing CVE-2026-73012 from Microsoft as a priority, checking Microsoft's advisory for the exact affected builds since no version ranges are given here. Until patched, restrict network access to Management Services to trusted management subnets and limit which low-privileged accounts can reach it, focusing first on hosts exposed to VPN, remote access, or broad internal user networks. Monitor for unusual authenticated access to the service, and re-check KEV/EPSS as exploitation likelihood may rise if a public proof-of-concept appears.
| Microsoft Windows Management Services (Windows component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Management Services allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.