Junglewise Threat Intelligence

CVE-2026-73022: Microsoft Windows Modern Device Management privilege escalation

CVE-2026-73022 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Modern Device Management (MDM) is a system component that manages device policies and configuration for enterprise environments. A use-after-free flaw in this component allows an authenticated local attacker to elevate their privileges, potentially gaining unauthorized access to sensitive system functions and data.

Technical details

A use-after-free vulnerability exists in the Windows Modern Device Management component. The flaw permits an authorized local attacker to execute privilege escalation through memory manipulation. The attack requires prior system access (authenticated/local), as indicated by the "authorized attacker" designation. Successful exploitation grants elevated privileges on the affected system. A patch or mitigation from Microsoft is presumed available given the formal advisory publication.

Affected products

  • Microsoft Windows Modern Device Management <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats