Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-42911: Windows AFD.sys Privilege Escalation Flaw Patched in June 2026 Update
Microsoft released a patch on June 9, 2026, for CVE-2026-42911, an Important-rated elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). The flaw could...
Windows TCP/IP Zero-Click Flaw Lets Attackers Gain SYSTEM Access
Microsoft’s June 2026 Patch Tuesday batch fixes a critical Windows networking flaw—CVE-2026-42904—that lets unauthenticated attackers escalate privileges to SYSTEM, the highest possible level...
CVE-2026-42836: Windows Elevation of Privilege via Race Condition in Function Discovery Service
On June 9, 2026, Microsoft released its monthly Patch Tuesday updates, tackling CVE-2026-42836—an elevation-of-privilege vulnerability in the Windows Function Discovery Service. The flaw, rated...
Microsoft Hotpatch Service Bug Lets Attackers Gain SYSTEM Privileges
June’s Patch Tuesday brought a new privilege escalation bug that server administrators need to prioritize: CVE-2026-42910, a hole in the Windows Hotpatch Monitoring Service. Microsoft disclosed the...
Microsoft Patches High-Severity Office Click-to-Run EoP Vulnerability CVE-2026-47293
On June 9, 2026, as part of its monthly Patch Tuesday release, Microsoft tackled a high-severity elevation-of-privilege vulnerability in Microsoft Office. The flaw, cataloged as CVE-2026-47293,...
CVE-2026-45653: Microsoft Patches Important Windows Kernel Elevation-of-Privilege Flaw in June 2026 Patch Tuesday
Microsoft’s June 9, 2026 security update addresses CVE-2026-45653, a Windows kernel elevation-of-privilege vulnerability that could allow an attacker to gain SYSTEM-level access on a compromised...
Microsoft Urges Patching of CVE-2026-45601: WinSock AFD Driver Exploit Leads to SYSTEM Access
Microsoft’s June 2026 Patch Tuesday closed a dangerous elevation-of-privilege hole in the Windows Ancillary Function Driver for WinSock (AFD). Tracked as CVE-2026-45601, the flaw grants a locally...
CVE-2026-45593: Windows SDK Privilege Escalation Forces Urgent Patching for Developer Environments
On June 9, 2026, Microsoft’s monthly security release included an unusual entry: CVE-2026-45593, an elevation-of-privilege vulnerability in the Windows Software Development Kit (SDK). The fix...
Patch now: Critical WinINet EoP bug CVE-2026-45592 gives attackers SYSTEM access.
Microsoft's June 2026 Patch Tuesday, released on June 9, brings a critical fix for CVE-2026-45592, an elevation-of-privilege vulnerability in the Windows Internet (WinINet) API library. The flaw,...
CVE-2026-42828: Windows ProjFS Flaw Lets Attackers Gain SYSTEM Rights
Microsoft’s June 2026 Patch Tuesday has delivered a critical fix for CVE-2026-42828, an elevation-of-privilege vulnerability in the Windows Projected File System (ProjFS). Rated Important with a...
Patch Tuesday Urgent: Fix CVE-2026-40371 EoP in Dynamics 365 On-Prem
{ "title": "CVE-2026-40371: Patch Tuesday EoP Risk in Microsoft Dynamics 365 On-Prem", "content": "On June 9, 2026, Microsoft dropped a security advisory for CVE-2026-40371 as part of its...
Microsoft Patches Windows Kernel Elevation-of-Privilege Flaw CVE-2026-48583 in June 2026 Patch Tuesday
Microsoft has pushed out a fix for a use-after-free vulnerability in the Windows kernel as part of its June 2026 security updates. Tracked as CVE-2026-48583, the local elevation-of-privilege flaw...