Junglewise Threat Intelligence

CVE-2026-77899: Microsoft Windows Security Center use-after-free privilege escalation

CVE-2026-77899 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Security Center is a built-in Windows component that manages antivirus and security settings. A use-after-free vulnerability allows an authenticated local attacker to elevate their privileges on the system, potentially gaining administrative access and full control over the machine.

Technical details

The vulnerability is a use-after-free condition in Windows Security Center that permits local privilege escalation. An authorized attacker with local access can trigger the use-after-free to achieve privilege elevation. The attack requires prior authentication/access to the system (not unauthenticated network-based). Successful exploitation results in elevated privileges, typically leading to system compromise. Patches from Microsoft are available through their security update channels.

Affected products

  • Microsoft Windows Security Center

Timeline

  • 2026-09-08: disclosed: CVE-2026-77899 published

References