Junglewise Threat Intelligence

CVE-2026-78457: Microsoft Windows Security Health Service use-after-free privilege escalation

CVE-2026-78457 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Security Health Service is a system component that monitors and reports the health status of Windows security features. A use-after-free memory corruption vulnerability allows an authenticated local attacker to execute arbitrary code with elevated privileges, potentially leading to full system compromise or malware installation.

Technical details

The vulnerability is a use-after-free (UAF) in Windows Security Health Service, a memory corruption flaw where the service attempts to access memory that has already been freed. This occurs in a component accessible to authenticated local users. An attacker with local access and valid credentials can trigger the vulnerability through a specific sequence of operations, allowing execution of arbitrary code in the context of the elevated service. Microsoft has released a patch; consult the MSRC advisory for patch availability and affected Windows versions.

Affected products

  • Microsoft Windows Security Health Service <UNKNOWN>

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References