securityonline.info 7/24/2026, 4:30:53 PM · external

CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM

CVE-2026-50454: Public PoC Shows Windows AppResolver Elevation of Privilege to SYSTEM
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE page discusses CVE-2026-50454, a serious elevation of privilege vulnerability in Microsoft Windows 11, specifically affecting versions 10.0.26100.0, 10.0.26200.0, and 10.0.28000.0. The vulnerability allows for a UAC (User Account Control) bypass, enabling malicious users with local administrator access to execute arbitrary code at a SYSTEM level without consent prompts. The flaw was disclosed by researcher David Carliez, who also published proof-of-concept code.

Microsoft issued patches in the July 2026 update (versions 10.0.26100.8875, 10.0.26200.8875, etc.) to mitigate this issue. The EPSS risk score is 0.4%. Users are advised to update their systems immediately to avoid potential exploitation.

View Primary Source Via securityonline.info

Article by CyberSIXT