CVE-2026-72958 – Windows Credential Guard Elevation of Privilege Vulnerability

CVSS 8.2 IMPORTANT Critical - Same Day Deployment

“A successful attack could turn existing local access into powerful VTL1 privileges, putting sensitive systems and data at greater risk.”

CVE-2026-72958 is a Critical elevation-of-privilege vulnerability in Windows Credential Guard caused by a double-free weakness. An authorized local attacker who successfully exploits the flaw could gain Virtual Trust Level 1 (VTL1) privileges. Exploitation requires high existing privileges and no user interaction. The vulnerability is not publicly disclosed and is not known to be exploited.

Key Details

Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-415
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.