CVE-2026-77899

Summary

Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.

Affected Software

VendorProductVersion RangeStatus
MicrosoftWindows 11 Version 24H210.0.26100.0 < 10.0.26100.9445affected
MicrosoftWindows 11 Version 25H210.0.26200.0 < 10.0.26200.9445affected
MicrosoftWindows 11 version 26H110.0.28000.0 < 10.0.28000.2954affected
MicrosoftWindows Server 20126.2.9200.0 < 6.2.9200.26349affected
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0 < 6.2.9200.26349affected

Weaknesses

  • CWE-416: CWE-416: Use After Free

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References