Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-42979: Exploit lets local attackers gain SYSTEM via Windows Push Notification race condition
Microsoft has disclosed a new elevation-of-privilege vulnerability in the Windows Push Notification service, tracked as CVE-2026-42979. Revealed on June 9, 2026, as part of this month's Patch Tuesday...
Patch Windows Push Notifications Bug Granting SYSTEM Access Now
Microsoft has patched a high-severity local privilege escalation vulnerability in the Windows Push Notifications service, tracked as CVE-2026-42977. Disclosed on June 9, 2026, as part of the...
Microsoft Patches Important Local Privilege Escalation Flaw in Windows Push Notifications (CVE-2026-42978)
Microsoft has released a security update to address a local privilege escalation vulnerability in the Windows Push Notifications service, tracked as CVE-2026-42978. The flaw, rated Important, could...
Patch Now: CVE-2026-42986 Graphics Bug Lets Local Users Reach SYSTEM.
Microsoft released CVE-2026-42986 as part of its June 2026 Patch Tuesday updates, addressing a high-severity elevation of privilege vulnerability in the Windows Graphics Component. The flaw,...
CVE-2026-42911: Windows AFD.sys Privilege Escalation Flaw Patched in June 2026 Update
Microsoft released a patch on June 9, 2026, for CVE-2026-42911, an Important-rated elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). The flaw could...
Windows TCP/IP Zero-Click Flaw Lets Attackers Gain SYSTEM Access
Microsoft’s June 2026 Patch Tuesday batch fixes a critical Windows networking flaw—CVE-2026-42904—that lets unauthenticated attackers escalate privileges to SYSTEM, the highest possible level...
CVE-2026-42836: Windows Elevation of Privilege via Race Condition in Function Discovery Service
On June 9, 2026, Microsoft released its monthly Patch Tuesday updates, tackling CVE-2026-42836—an elevation-of-privilege vulnerability in the Windows Function Discovery Service. The flaw, rated...
Microsoft Hotpatch Service Bug Lets Attackers Gain SYSTEM Privileges
June’s Patch Tuesday brought a new privilege escalation bug that server administrators need to prioritize: CVE-2026-42910, a hole in the Windows Hotpatch Monitoring Service. Microsoft disclosed the...
Microsoft Patches High-Severity Office Click-to-Run EoP Vulnerability CVE-2026-47293
On June 9, 2026, as part of its monthly Patch Tuesday release, Microsoft tackled a high-severity elevation-of-privilege vulnerability in Microsoft Office. The flaw, cataloged as CVE-2026-47293,...
CVE-2026-45653: Microsoft Patches Important Windows Kernel Elevation-of-Privilege Flaw in June 2026 Patch Tuesday
Microsoft’s June 9, 2026 security update addresses CVE-2026-45653, a Windows kernel elevation-of-privilege vulnerability that could allow an attacker to gain SYSTEM-level access on a compromised...
Microsoft Urges Patching of CVE-2026-45601: WinSock AFD Driver Exploit Leads to SYSTEM Access
Microsoft’s June 2026 Patch Tuesday closed a dangerous elevation-of-privilege hole in the Windows Ancillary Function Driver for WinSock (AFD). Tracked as CVE-2026-45601, the flaw grants a locally...
CVE-2026-45593: Windows SDK Privilege Escalation Forces Urgent Patching for Developer Environments
On June 9, 2026, Microsoft’s monthly security release included an unusual entry: CVE-2026-45593, an elevation-of-privilege vulnerability in the Windows Software Development Kit (SDK). The fix...