ZeroHour

CVE-2026-77905

mass

Use-After-Free Local Privilege Escalation in Windows WMI

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-77905 is a use-after-free memory corruption flaw (CWE-416) in the Windows Management Instrumentation (WMI) component of Microsoft Windows. A local, authorized attacker with low privileges can trigger the flaw, which requires a high-complexity set of conditions (likely a timing/state race in freed-memory handling) but no user interaction. Successful exploitation yields a local elevation of privilege with high impact on confidentiality, integrity, and availability, typically meaning code execution at elevated (e.g., SYSTEM-level) rights. All Windows systems running the affected WMI component are affected; the specific affected Windows versions/builds are not listed in the available data and should be confirmed against Microsoft's advisory. Exploitation status is currently quiet: no public proof-of-concept, not listed in CISA KEV, and a low ~0.2% EPSS probability of exploitation in the next 30 days.

What to do: Deploy Microsoft's Windows security update for CVE-2026-77905 from the relevant monthly cumulative update; because the available data does not list affected builds, verify the exact affected version range in Microsoft's advisory before scoping. Prioritize patching systems where low-privileged or untrusted users obtain interactive logon (workstations, RDS/terminal servers, shared kiosks), since the flaw is a local elevation of privilege. No public exploit or workaround is known; restricting local logon rights on sensitive hosts reduces practical risk while updates are rolled out.

Affected
Microsoft Windows (Windows Management Instrumentation component)
Estimated exposure
mass≈1 billion+ Windows endpoints (WMI is a core component present on every Windows installation) — WMI ships as an always-present core OS component, and the installed base of Windows desktops and servers is on the order of a billion devices, though practical exploit exposure is limited to systems where untrusted or low-privileged users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.