Junglewise Threat Intelligence

CVE-2026-58547: Microsoft Windows UPnP heap overflow in upnp.dll

CVE-2026-58547 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows 10 Version 21H2, Microsoft Windows 11 Version 24H2, Microsoft Windows Server 2022, Microsoft Windows 10 Version 1809, Microsoft Windows 10 Version 22H2, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Universal Plug and Play (UPnP) component, which is used by the operating system to discover and connect to networked devices like printers and routers. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level system privileges. This could allow them to bypass security restrictions or cause a system crash, potentially disrupting business operations.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows Universal Plug and Play (UPnP) library, specifically within upnp.dll. The flaw is triggered when the component improperly handles memory allocation during the processing of UPnP requests. An attacker with low-privileged local access can exploit this to execute code with elevated privileges or cause a denial-of-service (system crash). The attack requires local authentication but no user interaction. Microsoft has released security updates to address this issue across various Windows 10, 11, and Server versions.

Affected products

  • Microsoft Windows 10 Version 1809 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
  • Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows Server 2019 10.0.17763.0 to 10.0.17763.9020
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats