
CVE-2026-27915 Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-27915
Post summary
CVE-2026-27915 is a use‑after‑free vulnerability in Windows UPnP Device Host that allows a local attacker to elevate privileges; a link to the official CVE record is provided.
