Junglewise Threat Intelligence

CVE-2026-72958: Microsoft Windows Credential Guard double free privilege escalation

CVE-2026-72958 · Severity: high · CVSS 8.2 · Published 2026-09-08

Executive brief

Windows Credential Guard is a security feature that protects user credentials stored on a Windows system. A double-free memory vulnerability in this component allows an authorized local user to escalate their privileges to a higher level, potentially gaining full control of the affected system.

Technical details

A double-free vulnerability exists in Windows Credential Guard, a memory safety flaw where the same memory region is freed twice, leading to heap corruption. The vulnerability requires local access and authorization to trigger, but permits a local attacker to escalate privileges. The root cause involves improper memory management in the Credential Guard component. Successful exploitation allows privilege escalation to a higher integrity level on the affected system. A security patch from Microsoft is expected to address this issue.

Affected products

  • Microsoft Windows Credential Guard <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References