Missing-Authorization Local Privilege Escalation in Microsoft Data Sharing Service Client
AI analysis
CVE-2026-73014 is a missing authorization flaw (CWE-862) in the Data Sharing Service Client, a Microsoft component assigned by the Microsoft CNA. A local attacker who already holds a low-privileged authorized account on the machine can invoke the service without a required authorization check and elevate privileges. Successful exploitation yields high impact to confidentiality, integrity, and availability (CVSS 7.8), which typically means gaining elevated rights on the local system. Any system running the affected component is exposed, though the attack requires local access and is not remotely exploitable. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%; the fix shipped in Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws.
What to do: Apply the September 2026 Microsoft Patch Tuesday updates as soon as possible to remediate the missing authorization check. There is no public PoC or confirmed in-the-wild exploitation, but prioritize patching multi-user machines, terminals, and servers where untrusted users hold local accounts, since local elevation flaws are commonly chained with other vulnerabilities.
Affected
| Microsoft Data Sharing Service Client | — |
Estimated exposure
masshundreds of millions of Windows endpoints, assuming the component ships by default with supported Windows releases — The Microsoft CNA assignment and inclusion in September 2026 Patch Tuesday indicate an in-box component of the Windows client base (roughly 1+ billion devices), though only accounts with local access can trigger the flaw, so remotely…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.