Double free in Microsoft Windows and Windows Server - CVE-2026-72958
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local privileged user to elevate privileges.
The vulnerability exists due to double free in Windows Credential Guard when triggering a double-free condition locally. A local privileged user can exploit the double-free condition to elevate privileges.
Successful exploitation can grant Virtual Trust Level 1 (VTL1) privileges.
Affected software
Windows Server
How to mitigate CVE-2026-72958
Windows Server - update to 2025 10.0.26100.33438