Junglewise Threat Intelligence

CVE-2026-45599: Microsoft Windows use after free in Universal Plug and Play (upnp.dll)

CVE-2026-45599 · Severity: high · CVSS 8.1 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Windows component responsible for discovering and connecting to network devices like printers and routers. An attacker could exploit this flaw to remotely take control of a computer without any user interaction. This could lead to the theft of sensitive data, the installation of malware, or a complete system shutdown.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Universal Plug and Play (UPnP) library (upnp.dll) in Microsoft Windows. The flaw is triggered when the service incorrectly manages memory during the processing of network requests, allowing an unauthenticated attacker to achieve remote code execution (RCE). While the attack vector is network-based and requires no user interaction or privileges, the CVSS score reflects a high attack complexity, likely due to timing requirements or memory layout constraints necessary to successfully exploit the use-after-free condition. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Universal Plug and Play (UPnP) Service

Timeline

  • 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-06-09: patched: Security updates made available via Microsoft Security Update Guide.

References

Related threats