CVE-2026-58544: Windows Management Services Elevation of Privilege Vulnerability
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
Other sources
Windows Management Services Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires an authorized attacker with local access and low privileges. It is not described as remotely exploitable or requiring user interaction.
What is the potential impact of successful exploitation?
A successful attacker could elevate privileges locally. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability.
Which systems are identified as affected?
The listed affected software includes Microsoft Windows Management Services, Microsoft Windows 11, Windows Server 2025, and Windows 11 versions 24H2, 25H2, and 26H1.