Junglewise Threat Intelligence

CVE-2026-85360: Microsoft Windows Kernel use-after-free privilege escalation

CVE-2026-85360 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

A use-after-free vulnerability exists in the Windows Kernel that allows an authorized local user to gain elevated system privileges. An attacker with existing access to a Windows system could exploit this flaw to escalate their permissions and take full control of the machine, compromising system integrity and access to sensitive data.

Technical details

The vulnerability is a use-after-free condition in the Windows Kernel that allows a local, authenticated attacker to escalate privileges. The root cause involves improper memory management where freed memory is accessed, allowing arbitrary code execution with elevated privileges. This attack requires existing local access to the system; remote exploitation is not possible. A successful exploit grants the attacker SYSTEM-level privileges, enabling complete system compromise. Patches are expected to be available through Microsoft's regular security updates.

Affected products

  • Microsoft Windows Kernel

Timeline

  • 2026-09-08: disclosed

References

Related threats