ZeroHour

CVE-2026-73014

mass

Missing-Authorization Local Privilege Escalation in Microsoft Data Sharing Service Client

CVSS 3.1
7.8 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-73014 is a missing authorization flaw (CWE-862) in the Data Sharing Service Client, a Microsoft component assigned by the Microsoft CNA. A local attacker who already holds a low-privileged authorized account on the machine can invoke the service without a required authorization check and elevate privileges. Successful exploitation yields high impact to confidentiality, integrity, and availability (CVSS 7.8), which typically means gaining elevated rights on the local system. Any system running the affected component is exposed, though the attack requires local access and is not remotely exploitable. There is no known public proof-of-concept, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%; the fix shipped in Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws.

What to do: Apply the September 2026 Microsoft Patch Tuesday updates as soon as possible to remediate the missing authorization check. There is no public PoC or confirmed in-the-wild exploitation, but prioritize patching multi-user machines, terminals, and servers where untrusted users hold local accounts, since local elevation flaws are commonly chained with other vulnerabilities.

Affected
Microsoft Data Sharing Service Client
Estimated exposure
masshundreds of millions of Windows endpoints, assuming the component ships by default with supported Windows releases — The Microsoft CNA assignment and inclusion in September 2026 Patch Tuesday indicate an in-box component of the Windows client base (roughly 1+ billion devices), though only accounts with local access can trigger the flaw, so remotely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.

Weakness
CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1