Executive brief
Windows Modern Device Management (MDM) is a system component that allows IT administrators to manage corporate devices remotely. A use-after-free vulnerability in this component allows an authorized local attacker to elevate their privileges to system level, potentially gaining full control of a Windows computer.
Technical details
This vulnerability is a use-after-free memory corruption issue in the Windows Modern Device Management subsystem. The flaw allows an authorized local attacker to trigger memory operations on freed memory, resulting in arbitrary code execution with elevated privileges. Attack preconditions include local access to the system and some form of existing user authorization. Microsoft has released patches through their standard security update process to remediate this issue.
Affected products
- Microsoft Windows Modern Device Management (MDM) <UNKNOWN>
Timeline
- 2026-09-08: disclosed