Junglewise Threat Intelligence

CVE-2026-57092: Microsoft Windows VMSwitch use after free privilege escalation

CVE-2026-57092 · Severity: critical · CVSS 9.9 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A critical security vulnerability has been identified in the Windows Virtual Machine Switch (VMSwitch), a component used to manage network traffic for virtual machines. An authorized user on the network could exploit this flaw to gain elevated system privileges, potentially taking full control of the affected server or workstation. This could lead to unauthorized data access, service disruptions, or the ability to move laterally across the corporate network.

Technical details

This vulnerability is a Use-After-Free (UAF) class flaw (CWE-416) residing in the Windows VMSwitch driver. The vulnerability is triggered when the system improperly handles memory objects after they have been freed, allowing an attacker to execute arbitrary code or manipulate system memory. The attack vector is network-based and requires low-level authentication (PR:L), but it does not require user interaction. Because the vulnerability has a 'Changed' scope (S:C), an attacker could potentially escape a virtualized environment to impact the underlying host or other virtual machines. Microsoft has released security updates to address this issue in the July 2026 patch cycle.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2 (prior to July 2026 updates)
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1 (prior to July 2026 updates)
  • Microsoft Windows Server 2012 All editions (prior to July 2026 updates)

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats