← Back to CVE search

CVE-2026-27920

Windows Universal Plug and Play (UPnP) Device Host

Description

Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

CVSS 7.8EPSS 0.24%Risk 0.8
View source
Published
2026-04-14 18:17:01
Affected versions
unknown
Type
Core software
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Operating systems
Windows