ZeroHour

CVE-2026-77899

mass

Use-After-Free Local Privilege Escalation in Windows Security Center

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

A use-after-free flaw (CWE-416) exists in the Windows Security Center component of Microsoft Windows, where memory that has been freed is accessed again during service operation. An authorized attacker who already has valid low-privileged credentials on the local machine can trigger the flaw (high attack complexity, no user interaction required), causing the Security Center service to operate on freed memory. Successful exploitation yields elevation of privilege on the local system, with high impact on confidentiality, integrity, and availability per the CVSS score of 7.0. All Windows installations running the affected component are exposed in principle, although Microsoft has not published specific affected version ranges in the available data. Exploitation is not currently known: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% probability of exploitation in the next 30 days.

What to do: Monitor Microsoft's advisory and Windows Update for the security update addressing CVE-2026-77899, since the affected version ranges are not included in the available data. Until patched, minimize the number of users with local sign-in rights on sensitive Windows hosts and treat any low-privileged local code execution as a potential path to privilege escalation. Because exploitation likelihood is currently low (EPSS 0.2%, no KEV entry, no public PoC), prioritize patching within normal cycles rather than emergency maintenance windows.

Affected
Microsoft Windows (Security Center component)
Estimated exposure
mass≈1 billion+ Windows installations (Security Center is a built-in component) — Windows Security Center ships by default with Windows, which Microsoft has publicly reported as running on over a billion active devices, so the potential exposure is mass-scale even though the exact affected version ranges are unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.