ZeroHour

CVE-2026-73022

mass

Use-after-free local privilege escalation in Windows Modern Device Management (MDM)

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-73022 is a use-after-free memory-safety flaw (CWE-416) in the Windows Modern Device Management (MDM) component, scored 7.0 (High) on CVSS 3.1. To trigger it, an already-authorized local attacker with low privileges must cause the MDM component to use freed memory, a condition rated high in attack complexity and requiring no user interaction. Successful exploitation lets the attacker elevate privileges locally on the affected Windows host, with high impact on confidentiality, integrity, and availability on that machine. Any Windows system running the Modern Device Management component is potentially affected, though the available data does not specify exact affected version ranges. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS assigns a modest 0.2% probability of exploitation within 30 days.

What to do: Install Microsoft's patch for CVE-2026-73022 via Windows Update as part of the applicable monthly security release, and check Microsoft's advisory for the exact affected Windows version ranges. Until systems are patched, limit local interactive and low-privilege logon access on shared Windows hosts and review event logs for local privilege-escalation indicators. No workarounds or public proof-of-concept exploits are currently known, and exploitation likelihood is currently rated low by EPSS.

Affected
Microsoft Windows Modern Device Management (MDM) component
Estimated exposure
massorder of hundreds of millions to ~1 billion Windows 10/11 devices (modern Windows install base >1B, and the MDM component ships broadly with it) — The affected component is bundled with modern Windows desktop operating systems, whose installed base is publicly counted at over one billion devices, so the plausibly affected population is mass-scale even though only locally exploitable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.