CVE-2026-73022
massUse-after-free local privilege escalation in Windows Modern Device Management (MDM)
CVE-2026-73022 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component, scored 7.0 (High) on CVSS 3.1. To trigger it, an already-authorized local attacker with low privileges must cause the MDM component to use freed memory, a condition rated high in attack complexity and requiring no user interaction. Successful exploitation lets the attacker elevate privileges locally on the affected Windows host, with high impact on confidentiality, integrity, and availability on that machine. Any Windows system running the Modern Device Management component is potentially affected, though the available data does not specify exact affected version ranges. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a modest 0.2% probability of exploitation within 30 days.
What to do: Install Microsoft's patch for CVE-2026-73022 via Windows Update as part of the applicable monthly security release, and check Microsoft's advisory for the exact affected Windows version ranges. Until systems are patched, limit local interactive and low-privilege logon access on shared Windows hosts and review event logs for local privilege-escalation indicators. No workarounds or public proof-of-concept exploits are currently known, and exploitation likelihood is currently rated low by EPSS.
| Microsoft Windows Modern Device Management (MDM) component | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.