Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft’s ODBC Driver Flaw Needs an Inventory, Not a Blind Patch—Here’s Your Action Plan
Microsoft published a new elevation-of-privilege vulnerability in its ODBC Driver for SQL Server on July 14, 2026. The advisory, tracked as CVE-2026-42990, arrived without a security patch, a list of...
CVE-2026-42900 Update: Network Attackers Can Exploit Windows App Store for Privilege Escalation
Microsoft issued a high-priority fix on July 14, 2026, for CVE-2026-42900, an elevation-of-privilege vulnerability with a CVSS score of 8.1. The flaw, buried inside the Windows App Store component,...
Google Fixes Chrome for Android Flaw That Could Hand Your Device to Local Attackers
On June 30, Google disclosed a serious vulnerability in Chrome for Android that could allow a local attacker to seize higher privileges on a device. The fix arrived in version 150.0.7871.47, and...
A Linux Graphics Bug Can Give Attackers Root — and Your Windows Machine Isn’t Immune
A newly disclosed vulnerability in the Linux kernel’s Direct Rendering Manager (DRM) subsystem can allow an unprivileged local user to gain root access. Tracked as CVE-2026-46215, the flaw targets...
Critical Linux Kernel Bug Exposes WSL2 and Container Hosts — Patch Now
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-43499 and named GhostLock, lets attackers break out of sandboxes and seize root control of affected systems. The flaw reaches beyond...
CVE-2026-54998: Why Microsoft's Confidence Rating is Critical for Exchange Online EoP Defense
Microsoft’s Security Response Center (MSRC) has published CVE-2026-54998, a new elevation-of-privilege (EoP) vulnerability affecting Exchange Online. What makes this disclosure different from the...
CVE-2026-26145: Microsoft Flags Privilege Escalation Flaw in Azure Synapse Analytics
Microsoft has confirmed a new privilege escalation vulnerability in its cloud analytics service, Azure Synapse, tracked as CVE-2026-26145. The flaw, disclosed through the company's Security Update...
Windows Push Notifications Race Condition Lets Attackers Escalate to SYSTEM
Microsoft’s June 2026 Patch Tuesday brought a critical security fix for a local privilege escalation vulnerability in the Windows Push Notifications service. Tracked as CVE-2026-42991, the flaw...
CVE-2026-42979: Exploit lets local attackers gain SYSTEM via Windows Push Notification race condition
Microsoft has disclosed a new elevation-of-privilege vulnerability in the Windows Push Notification service, tracked as CVE-2026-42979. Revealed on June 9, 2026, as part of this month's Patch Tuesday...
Patch Windows Push Notifications Bug Granting SYSTEM Access Now
Microsoft has patched a high-severity local privilege escalation vulnerability in the Windows Push Notifications service, tracked as CVE-2026-42977. Disclosed on June 9, 2026, as part of the...
Microsoft Patches Important Local Privilege Escalation Flaw in Windows Push Notifications (CVE-2026-42978)
Microsoft has released a security update to address a local privilege escalation vulnerability in the Windows Push Notifications service, tracked as CVE-2026-42978. The flaw, rated Important, could...
Patch Now: CVE-2026-42986 Graphics Bug Lets Local Users Reach SYSTEM.
Microsoft released CVE-2026-42986 as part of its June 2026 Patch Tuesday updates, addressing a high-severity elevation of privilege vulnerability in the Windows Graphics Component. The flaw,...