Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-26132: Windows Kernel Use-After-Free Vulnerability Requires Immediate Patch Tuesday Attention
Microsoft has confirmed CVE-2026-26132 as a critical Windows Kernel use-after-free vulnerability that allows authorized local users to gain elevated privileges on affected systems. The security flaw,...
Microsoft Patches Critical .NET 10 Linux Privilege Escalation Vulnerability CVE-2026-26131
Microsoft released a security patch on March 10, 2026 addressing CVE-2026-26131, a critical elevation-of-privilege vulnerability in .NET 10 for Linux systems. The flaw stems from incorrect default...
CVE-2026-26128: Critical Windows SMB Server Privilege Escalation Vulnerability Analysis
Microsoft has cataloged CVE-2026-26128 as an elevation-of-privilege defect in the Windows SMB Server that allows an authorized (local) attacker to escalate privileges on affected systems. This...
Microsoft Patches Critical SCOM Privilege Escalation Vulnerability CVE-2026-20967
Microsoft released a security update on March 10, 2026 addressing an authenticated, network-based elevation-of-privilege vulnerability in System Center Operations Manager tracked as CVE-2026-20967....
Microsoft Confirms Critical DWM Privilege Escalation Vulnerability CVE-2026-25189
Microsoft has officially documented CVE-2026-25189, a confirmed use-after-free vulnerability in the Windows Desktop Window Manager (DWM) Core Library that enables local privilege escalation. The...
CVE-2026-25175: Critical Windows NTFS Privilege Escalation Vulnerability Discovered
Microsoft has documented a new elevation-of-privilege vulnerability in the Windows NTFS file system driver, designated CVE-2026-25175. The security flaw involves an out-of-bounds read in the NTFS...
CVE-2026-25170: Windows Hyper-V Use-After-Free Vulnerability Enables Local Privilege Escalation
Microsoft documented CVE-2026-25170 on March 10, 2026, a critical use-after-free vulnerability in Windows Hyper-V that enables local privilege escalation. The Common Weakness Enumeration identifier...
Microsoft Patches Critical Windows Device Association Service Race Condition in March 2026 Patch Tuesday
Microsoft's March 10, 2026 Patch Tuesday security update addresses a critical vulnerability in the Windows Device Association Service that could allow local privilege escalation. Tracked as...
Microsoft Patches Critical AFD.sys Privilege Escalation Vulnerability CVE-2026-24293 in March 2026 Emergency Update
Microsoft released emergency security fixes on March 10, 2026, addressing CVE-2026-24293, a high-impact elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock...
CVE-2026-24290: Windows ProjFS Kernel Privilege Escalation Vulnerability Analysis
Microsoft has assigned CVE-2026-24290 to a newly discovered elevation of privilege vulnerability in the Windows Projected File System (ProjFS) driver. The vulnerability allows authenticated attackers...
CVE-2026-24285: Critical Win32k Local Privilege Escalation Vulnerability Patched by Microsoft
Microsoft has patched a critical local privilege escalation vulnerability in the Windows Win32k subsystem, tracked as CVE-2026-24285. This security flaw allows authenticated local users to gain...
Microsoft Patches Critical ReFS Privilege Escalation Vulnerability CVE-2026-23673
Microsoft released a critical security update on March 10, 2026, addressing CVE-2026-23673, a local elevation-of-privilege vulnerability in the Windows Resilient File System (ReFS). The...