CVE-2026-27919

7.8

Microsoft · Windows

An untrusted pointer dereference vulnerability in the Windows UPnP Device Host allows an authenticated local attacker to achieve privilege escalation on affected systems.

Executive summary

A vulnerability in the Windows UPnP Device Host allows an authenticated local user to escalate privileges, posing a significant risk to system integrity and security.

Vulnerability

This is an untrusted pointer dereference flaw (CWE-822) within the Windows UPnP Device Host. The vulnerability requires the attacker to possess local authenticated access to the system to trigger the dereference and escalate privileges.

Business impact

Successful exploitation of this vulnerability allows an attacker to elevate their privileges locally, potentially gaining full control over the compromised system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized data access, the installation of malicious software, or the complete compromise of the host machine.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide for CVE-2026-27919 to all affected systems.

Proactive Monitoring: Monitor system logs for unusual process activity or attempts to interact with the UPnP Device Host service that deviate from standard operational baselines.

Compensating Controls: Ensure that local user permissions are strictly managed according to the principle of least privilege, which limits the potential damage an attacker can cause if they successfully exploit a local vulnerability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the deployment of the vendor-supplied patches to all affected Windows versions. While local access is required, the ability to escalate privileges makes this a critical issue for internal security, and immediate remediation is necessary to prevent potential lateral movement or system takeover by malicious actors.

More Microsoft CVEs

Sources