securityonline.info 7/21/2026, 3:21:50 PM · external

Windows privilege escape bug CVE-2026-42980 patched by Microsoft

Windows privilege escape bug CVE-2026-42980 patched by Microsoft
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

CVE- 2026-42980 is a high-severity privilege escalation vulnerability in Microsoft Windows, affecting several versions of Windows 10. Assigned a CVSS score of 7.8, it allows low-privileged users to gain SYSTEM level access due to an integer underflow in the NT kernel's WMI serialization code. The flaw has not yet been confirmed to be exploited in the wild, but a proof-of-concept has been released, increasing the urgency for patching. Microsoft issued a fix in the June 2026 Patch Tuesday, and users are advised to update their systems to specific patched versions to mitigate the risk.

View Primary Source Via securityonline.info

Article by CyberSIXT