Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-35436: Microsoft Patches Important Office Click-to-Run Elevation-of-Privilege Flaw
Microsoft rolled out its scheduled Patch Tuesday updates for May 2026, addressing a newly disclosed elevation-of-privilege vulnerability in Office Click-to-Run. CVE-2026-35436, rated Important, could...
Hyper-V Guest-to-Host Escape: Patch Critical CVE-2026-40402 Now
Microsoft’s May 2026 Patch Tuesday landed with a critical security update that Hyper-V administrators cannot afford to ignore. CVE-2026-40402, a use-after-free vulnerability in the Windows Hyper-V...
Microsoft patched CVE-2026-40398 in May 2026, an Important privilege escalation vulnerability in Windows Remote Desktop Services that allows a low-privileged authenticated attacker to gain SYSTEM priv
Microsoft's May 2026 Patch Tuesday rollout addressed 78 security vulnerabilities, among them CVE-2026-40398—an elevation-of-privilege bug in Windows Remote Desktop Services (RDS) scored at CVSS 7.8...
Microsoft May Patch Tuesday Fixes Critical CLFS Elevation of Privilege Bug
Microsoft’s May 12, 2026 Patch Tuesday includes a fix for CVE-2026-40397, an Important-severity elevation-of-privilege vulnerability in the Windows Common Log File System (CLFS) driver. Public...
CVE-2026-34340: Windows ProjFS Patch Fixes Critical EoP Flaw
Microsoft addressed a critical elevation-of-privilege (EoP) vulnerability in the Windows Projected File System (ProjFS) as part of its May 2026 Patch Tuesday updates. The flaw, tracked as...
Apply May 2026 Patch for Windows Telephony EoP Flaw CVE-2026-34338
On May 12, 2026, Microsoft published details on CVE-2026-34338, a new elevation-of-privilege (EoP) vulnerability affecting the Windows Telephony Service. The disclosure arrived as part of the...
CVE-2026-34337 Windows Cloud Files Driver Bug Grants SYSTEM — Patch Now
Microsoft has listed a new elevation-of-privilege vulnerability under CVE-2026-34337 in its Security Update Guide, affecting the Windows Cloud Files Mini Filter Driver. The flaw, rated Important by...
CVE-2026-34334 Windows TCP/IP Bug: Patch Now for SYSTEM Access
Microsoft has flagged CVE-2026-34334, a Windows TCP/IP privilege escalation vulnerability, with a critical exploitability assessment, pushing it to the top of the patch priority list for system...
CVE-2026-33838: Windows MSMQ Bug Gives SYSTEM Access via Malformed Message
Microsoft disclosed a critical elevation-of-privilege vulnerability in its legacy Message Queuing service as part of the May 2026 Patch Tuesday releases. Tracked as CVE-2026-33838, the flaw allows a...
Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow
CVE-2026-33837 landed on the May 2026 Patch Tuesday with an Important severity rating. It’s a local elevation-of-privilege vulnerability inside tcpip.sys, the kernel-mode driver that handles the...
CVE-2026-33835: Microsoft Patches Windows Cloud Files Elevation of Privilege Flaw in May 2026 Patch Tuesday
Microsoft fixed an elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver as part of its May 2026 Patch Tuesday updates. The flaw, tracked as CVE-2026-33835, was disclosed...
Microsoft Patches Rich Text Edit Control Privilege Escalation (CVE-2026-32170) in May 2026 Patch Tuesday
Microsoft's May 12, 2026 Patch Tuesday release addresses CVE-2026-32170, an elevation-of-privilege vulnerability in the Windows Rich Text Edit Control. The flaw, disclosed in the Microsoft Security...