Junglewise Threat Intelligence

CVE-2026-44805: Microsoft Windows Network Controller Host Agent use after free

CVE-2026-44805 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A vulnerability in the Windows Network Controller Host Agent could allow a user with basic access to a system to crash the service. This component is responsible for managing network infrastructure in software-defined networking environments. An exploit would result in a local denial-of-service, potentially disrupting network management operations on the affected host.

Technical details

This vulnerability is classified as a use-after-free (CWE-416) and untrusted pointer dereference (CWE-822) within the Windows Network Controller (NC) Host Agent. An attacker with low-privileged local access can trigger the flaw without any user interaction. The root cause involves the service attempting to use a memory pointer after it has been freed or improperly validated, leading to a crash of the host agent. Successful exploitation results in a loss of availability for the affected component. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Network Controller (NC) Host Agent

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References