Junglewise Threat Intelligence

CVE-2026-58637: Microsoft Windows Client-Side Caching Service privilege escalation

CVE-2026-58637 · Severity: high · CVSS 7 · Published 2026-07-14

Executive brief

A security vulnerability exists in the Windows Client-Side Caching (CSC) Service, which manages offline access to network files. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A use-after-free (CWE-416) vulnerability exists within the Windows Client-Side Caching (CSC) Service. The flaw is triggered when the service incorrectly manages memory objects during file caching operations, allowing an attacker to reuse a memory pointer after it has been freed. To exploit this, an attacker must have local access to the target system and execute a specially crafted application. Successful exploitation enables the attacker to gain SYSTEM privileges. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats