Junglewise Threat Intelligence

CVE-2026-85921: Microsoft Windows Secure Kernel Mode double free privilege escalation

CVE-2026-85921 · Severity: high · CVSS 8.2 · Published 2026-09-14

Executive brief

A double-free memory vulnerability exists in Windows Secure Kernel Mode that allows an authorized user to elevate their privileges on a local machine. An attacker with valid user credentials can exploit this flaw to gain system-level access, potentially enabling them to install malware, steal sensitive data, or take full control of the device.

Technical details

A double-free vulnerability in the Windows Secure Kernel Mode memory allocator permits a local attacker with valid user privileges to trigger the freeing of the same memory block twice, leading to memory corruption. The vulnerable component is part of Windows kernel security isolation, which isolates sensitive security operations. Exploitation requires local access with authorized user privileges; no network connectivity or elevated initial permissions are required. A successful exploit results in privilege escalation to system level (SYSTEM or kernel context). Microsoft has released a security update addressing this vulnerability; affected systems should apply the patch immediately.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-14: disclosed

References

Related threats