SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77500

HIGH · CVSS 7.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Windows Device Association Service contains a vulnerability that allows an authorized attacker to exploit a release of an invalid pointer or reference, enabling local privilege escalation. This could lead to unauthorized access to sensitive system resources or administrative capabilities. Organizations using affected Windows systems should prioritize patching this vulnerability to mitigate potential risks.

CVE
CVE-2026-77500
Severity
HIGH
CVSS
7.8
EPSS
0.33%
Windows

Original NVD Description

Release of invalid pointer or reference in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)