CVE-2026-78457
massUse-After-Free Elevation of Privilege in Microsoft Windows Security Health Service
CVE-2026-78457 is a use-after-free memory-safety flaw (CWE-416) in the Windows Security Health Service, a component that ships with Microsoft Windows. A local attacker who already holds low-privilege code execution on the host can trigger the flaw by causing the service to access freed memory, and the high attack complexity rating (AC:H) suggests specific timing or memory-layout conditions are required. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability once higher-privilege access is obtained. Affected users are any Windows deployments running the Security Health Service; the available data does not specify affected Windows version ranges, so defenders should consult the Microsoft advisory for the exact list. There is currently no known exploitation in the wild, no public proof-of-concept, and the vulnerability is not in CISA's KEV catalog, with EPSS estimating only a 0.2% chance of exploitation in the next 30 days.
What to do: Apply the Microsoft security update addressing the Windows Security Health Service as soon as it is released, prioritizing multi-user hosts such as terminal/RDS servers where local low-privilege accounts are more readily available to attackers. No public exploit or workaround is currently known, and the high attack complexity plus local-only vector make standard patch-cycle remediation reasonable for most environments; verify patch status once Microsoft publishes the fixed builds.
| Microsoft Windows Security Health Service (component of Windows) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Security Health Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2022, windows server 2025
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.