Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch now: Critical WinINet EoP bug CVE-2026-45592 gives attackers SYSTEM access.
Microsoft's June 2026 Patch Tuesday, released on June 9, brings a critical fix for CVE-2026-45592, an elevation-of-privilege vulnerability in the Windows Internet (WinINet) API library. The flaw,...
CVE-2026-42828: Windows ProjFS Flaw Lets Attackers Gain SYSTEM Rights
Microsoft’s June 2026 Patch Tuesday has delivered a critical fix for CVE-2026-42828, an elevation-of-privilege vulnerability in the Windows Projected File System (ProjFS). Rated Important with a...
Patch Tuesday Urgent: Fix CVE-2026-40371 EoP in Dynamics 365 On-Prem
{ "title": "CVE-2026-40371: Patch Tuesday EoP Risk in Microsoft Dynamics 365 On-Prem", "content": "On June 9, 2026, Microsoft dropped a security advisory for CVE-2026-40371 as part of its...
Microsoft Patches Windows Kernel Elevation-of-Privilege Flaw CVE-2026-48583 in June 2026 Patch Tuesday
Microsoft has pushed out a fix for a use-after-free vulnerability in the Windows kernel as part of its June 2026 security updates. Tracked as CVE-2026-48583, the local elevation-of-privilege flaw...
Microsoft Windows Storage EoP Flaw Grants SYSTEM Access—Patch Now
Microsoft dropped a security bombshell on June 9, 2026, with the publication of CVE-2026-47648, a critical elevation-of-privilege vulnerability burrowed deep inside the Windows Storage subsystem. The...
Microsoft Patches CVE-2026-45605 Windows Bluetooth Use-After-Free Flaw
Microsoft patched a critical elevation-of-privilege vulnerability in the Windows Bluetooth Service on June 9, 2026, closing a use-after-free bug that could allow attackers to gain SYSTEM-level...
Windows PCA Bug Lets Local Attackers Seize SYSTEM Rights—Patch Now
Microsoft has disclosed a local elevation-of-privilege (EoP) vulnerability in the Windows Program Compatibility Assistant (PCA) Service, tracked as CVE-2026-45487. The advisory, released on June 9,...
CVE-2026-40404: Critical Windows UDFS Elevation of Privilege Flaw Patched – What You Need to Know
Microsoft released a patch for CVE-2026-40404 on June 9, 2026, closing a high-severity elevation-of-privilege vulnerability in the Windows Universal Disk Format (UDFS) file system driver. The flaw...
Critical UDFS Elevation-of-Privilege Flaw (CVE-2026-40409) Patched in June 2026 Windows Update
Microsoft pushed out a security update on June 9, 2026 that fixes CVE-2026-40409, an elevation-of-privilege vulnerability in the Windows Universal Disk Format (UDF) file system driver. The flaw,...
New Windows DNS Client EoP Bug: Why Microsoft's Low Confidence Rating Sparks Patch Debate
CVE-2026-41108, a newly published elevation-of-privilege vulnerability in the Windows DNS Client, has surfaced as part of Microsoft’s June 2026 security update batch. While the technical details...
Linux kernel one-bit bug CVE-2026-46300 gives root access; update WSL2 now.
The Linux kernel has a new local privilege-escalation vulnerability that requires immediate attention. Tracked as CVE-2026-46300, the flaw is a one-bit bug in the kernel’s networking stack that can...
Microsoft Patches CVE-2026-41091: Defender Engine EoP Fixed in v1.1.26040.8
Microsoft patched a high-severity elevation-of-privilege vulnerability in its Malware Protection Engine on May 20, 2026. The flaw, tracked as CVE-2026-41091, could allow an attacker to gain...