Junglewise Threat Intelligence

CVE-2026-77905: Microsoft Windows Management Instrumentation use-after-free privilege escalation

CVE-2026-77905 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Management Instrumentation (WMI) is a system component that allows administrators and authorized software to manage and monitor Windows computers. A use-after-free vulnerability in WMI could allow an attacker with local system access to run malicious code with elevated privileges, potentially gaining full control of the computer and compromising all data and services running on it.

Technical details

The vulnerability is a use-after-free memory safety issue in Windows Management Instrumentation. The defect allows an authorized attacker with local access to trigger a code path that accesses memory that has already been freed, enabling arbitrary code execution with elevated privileges. The vulnerability requires local authentication and user-level access to exploit. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows Management Instrumentation

Timeline

  • 2026-09-08: disclosed

References

Related threats