Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows Bluetooth RFCOMM Driver Race Condition Exposes Kernel to Privilege Escalation Attacks
Microsoft has disclosed a critical kernel-level vulnerability in the Windows Bluetooth RFCOMM Protocol Driver that enables local privilege escalation attacks. CVE-2026-23671 represents a race...
CVE-2026-23660: Windows Admin Center Azure Portal Privilege Escalation Vulnerability Explained
Microsoft's security tracker lists CVE-2026-23660 as an elevation of privilege vulnerability affecting Windows Admin Center when accessed through the Azure Portal. The vulnerability appears in...
CVE-2026-26125: Microsoft Flags Critical Payment Flaw with High Confidence Metric
Microsoft has disclosed a critical elevation-of-privilege vulnerability in its Payment Orchestrator Service, designated CVE-2026-26125, with the company assigning a high confidence rating to its...
Azure Compute Gallery regex flaw lets authenticated attackers gain local admin rights
Microsoft has disclosed a significant security vulnerability in Azure Compute Gallery that could allow authenticated attackers to escalate privileges locally within cloud environments....
CVE-2026-26119 in Windows Admin Center lets low-privileged users gain admin rights; patch now
Microsoft has issued an urgent security update addressing a critical privilege escalation vulnerability in Windows Admin Center (WAC) tracked as CVE-2026-26119, which could allow authenticated...
CVE-2026-26119: Critical Windows Admin Center Privilege Escalation Vulnerability Patched
Microsoft has issued an urgent security update addressing a critical privilege escalation vulnerability in Windows Admin Center (WAC) tracked as CVE-2026-26119, which carries a CVSS score of 8.8...
CVE-2025-49809: Critical MTR Privilege Escalation Bug Fixed - Windows Security Alert
A critical security vulnerability in the widely-used network diagnostic tool MTR (My TraceRoute) has been patched after researchers discovered it could allow attackers to execute arbitrary code with...
MySQL CVE-2025-50077: Critical DoS Vulnerability in InnoDB/Optimizer Paths
A newly disclosed critical vulnerability in MySQL Server, tracked as CVE-2025-50077, allows high-privileged attackers to cause sustained denial-of-service conditions by exploiting flaws in the...
Urgent: 'Looney Tunables' glibc Exploit Grants Root on Azure Linux and Other Distros – Patch Now
A severe privilege escalation vulnerability in the GNU C Library (glibc) that affects a wide swath of Linux distributions—including Microsoft’s own Azure Linux—is now under active exploitation,...
CVE-2023-29403: Critical Go Runtime Privilege Escalation Vulnerability Explained
A critical security vulnerability in the Go programming language runtime has exposed a fundamental flaw in how Go handles Unix setuid/setgid binaries, creating potential privilege escalation vectors...
CVE-2010-0291: The Linux Kernel's do_mremap Memory Management Vulnerability Explained
In 2010, a critical vulnerability in the Linux kernel's memory management subsystem sent shockwaves through the open-source community, exposing fundamental flaws in how operating systems handle...
CVE-2026-26119: Critical Privilege Escalation Vulnerability in Windows Admin Center
Microsoft has disclosed a critical elevation-of-privilege vulnerability in Windows Admin Center (WAC) tracked as CVE-2026-26119, exposing a fundamental trust-model failure in the widely-used...