Junglewise Threat Intelligence

CVE-2026-72965: Microsoft Windows WebClient Service use-after-free privilege escalation

CVE-2026-72965 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

The Windows WebClient Service is a core component that enables users to access and manage files on remote web servers. A use-after-free vulnerability allows an authorized local user to execute code with elevated privileges, potentially compromising system security and administrative control of the affected machine.

Technical details

A use-after-free vulnerability exists in the Windows WebClient Service that can be triggered by an authorized local attacker. The vulnerability arises from improper memory management when handling service operations, allowing an attacker to reference freed memory and execute arbitrary code in the context of the privileged service. Exploitation requires local access and valid credentials but does not require user interaction. A successful exploit results in privilege escalation to SYSTEM or service-level privileges. Microsoft has released patches as part of their regular security updates.

Affected products

  • Microsoft Windows WebClient Service

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References