You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-40408
About this tag
CVE-2026-40408 is an Important-rated elevation-of-privilege vulnerability in the Windows WAN ARP Driver, disclosed by Microsoft on May 12, 2026. It affects supported Windows client and server releases and allows a locally authenticated attacker to gain SYSTEM privileges by exploiting a use-after-free flaw. The vulnerability resides in kernel-mode driver territory, carries a CVSS base score of 7.8, and is not a remote worm, public zero-day, or known to be exploited in the wild. Discussions on WindowsForum.com cover the technical details, affected systems, and mitigation strategies for CVE-2026-40408, emphasizing the risk of local privilege escalation to SYSTEM.
Microsoft disclosed CVE-2026-40408 on May 12, 2026, as an Important-rated Windows WAN ARP Driver elevation-of-privilege vulnerability that affects supported Windows client and server releases and allows a locally authenticated attacker to gain SYSTEM privileges after exploiting a use-after-free...