Executive brief
Windows Security Center is a built-in Windows component that manages antivirus and security settings. A use-after-free vulnerability allows an authenticated local attacker to elevate their privileges on the system, potentially gaining administrative access and full control over the machine.
Technical details
The vulnerability is a use-after-free condition in Windows Security Center that permits local privilege escalation. An authorized attacker with local access can trigger the use-after-free to achieve privilege elevation. The attack requires prior authentication/access to the system (not unauthenticated network-based). Successful exploitation results in elevated privileges, typically leading to system compromise. Patches from Microsoft are available through their security update channels.
Affected products
- Microsoft Windows Security Center
Timeline
- 2026-09-08: disclosed: CVE-2026-77899 published