CVE-2026-85921

8.2

Microsoft · Windows 11

A double free vulnerability in the Windows Secure Kernel Mode allows an authenticated attacker with high privileges to achieve local privilege escalation.

Executive summary

A high-severity double free vulnerability in Microsoft Windows 11 Secure Kernel Mode permits locally authenticated attackers to escalate privileges and compromise system integrity.

Vulnerability

The vulnerability is a double free flaw (CWE-415) located within the Windows Secure Kernel Mode. Successful exploitation requires an attacker to already possess high privileges on the local system to execute the necessary code.

Business impact

The vulnerability carries a CVSS score of 8.2, reflecting its capacity for total system impact once local execution is achieved. An attacker successfully exploiting this flaw could gain full control over the kernel, leading to complete system compromise, unauthorized data access, and the potential for persistent malware installation.

Remediation

Immediate Action: Update affected Microsoft Windows 11 systems to build 10.0.28000.2956 or later immediately to resolve the memory management error.

Proactive Monitoring: Review system access logs for suspicious administrative activity or kernel-mode crash events that may indicate exploitation attempts.

Compensating Controls: Ensure strict adherence to the principle of least privilege to limit the number of accounts possessing the high-level permissions required to trigger this vulnerability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of kernel-level vulnerabilities, administrators must prioritize the deployment of the security update to version 10.0.28000.2956. While the vulnerability requires existing high privileges, the risk of total system compromise necessitates prompt remediation to prevent lateral movement or further escalation by compromised accounts.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources