CVE-2026-77899
massUse-After-Free Local Privilege Escalation in Windows Security Center
A use-after-free flaw (CWE-416) exists in the Windows Security Center component of Microsoft Windows, where memory that has been freed is accessed again during service operation. An authorized attacker who already has valid low-privileged credentials on the local machine can trigger the flaw (high attack complexity, no user interaction required), causing the Security Center service to operate on freed memory. Successful exploitation yields elevation of privilege on the local system, with high impact on confidentiality, integrity, and availability per the CVSS score of 7.0. All Windows installations running the affected component are exposed in principle, although Microsoft has not published specific affected version ranges in the available data. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation in the next 30 days.
What to do: Monitor Microsoft's advisory and Windows Update for the security update addressing CVE-2026-77899, since the affected version ranges are not included in the available data. Until patched, minimize the number of users with local sign-in rights on sensitive Windows hosts and treat any low-privileged local code execution as a potential path to privilege escalation. Because exploitation likelihood is currently low (EPSS 0.2%, no KEV entry, no public PoC), prioritize patching within normal cycles rather than emergency maintenance windows.
| Microsoft Windows (Security Center component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.