Description
Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a use‑after‑free defect in Windows Security Center. It permits an attacker who already has local user access to take advantage of a freed memory reference in order to execute privileged code. As a result, a non‑privileged user could gain rights equivalent to a local administrator, potentially leading to full system compromise. Based on the description, it is inferred that the attack vector is from an authorized local user.

Affected Systems

The affected systems are Microsoft Windows 11 24H2, Windows 11 25H2, Windows 11 26H1, and Windows Server 2012 (including the Server Core installation).

Risk and Exploitability

The CVSS score of 7 indicates high severity. The EPSS score of < 1% indicates a very low exploitation probability, and the flaw is not yet listed in the CISA KEV catalog, suggesting that exploitation is not widespread at present. The exploit requires local user privileges and functions via the Security Center component, so the attack path is limited to a machine where the user is already authenticated or has physical access. Based on the description, it is inferred that the attack vector is local to the machine.

Generated by OpenCVE AI on September 9, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch detailed on the MSRC advisory link.
  • If the patch is not yet available, restrict or disable the Windows Security Center service to prevent the use‑after‑free from being triggered.
  • Remove or limit local user permissions that are unnecessary to reduce the attack surface for privilege escalation.

Generated by OpenCVE AI on September 9, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012 (server Core Installation)
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012 (server Core Installation)

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Security Center allows an authorized attacker to elevate privileges locally.
Title Windows Security Center Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2012 Windows Server 2012 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:30.090Z

Reserved: 2026-08-21T17:26:55.612Z

Link: CVE-2026-77899

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:19.959Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:40.133

Modified: 2026-09-16T15:09:21.767

Link: CVE-2026-77899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T21:05:38Z

Weaknesses