Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2026-33838: Windows MSMQ Bug Gives SYSTEM Access via Malformed Message
Microsoft disclosed a critical elevation-of-privilege vulnerability in its legacy Message Queuing service as part of the May 2026 Patch Tuesday releases. Tracked as CVE-2026-33838, the flaw allows a...
Patch Tuesday fixes CVE-2026-33837: Local SYSTEM access via tcpip.sys heap overflow
CVE-2026-33837 landed on the May 2026 Patch Tuesday with an Important severity rating. It’s a local elevation-of-privilege vulnerability inside tcpip.sys, the kernel-mode driver that handles the...
CVE-2026-33835: Microsoft Patches Windows Cloud Files Elevation of Privilege Flaw in May 2026 Patch Tuesday
Microsoft fixed an elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver as part of its May 2026 Patch Tuesday updates. The flaw, tracked as CVE-2026-33835, was disclosed...
Microsoft Patches Rich Text Edit Control Privilege Escalation (CVE-2026-32170) in May 2026 Patch Tuesday
Microsoft's May 12, 2026 Patch Tuesday release addresses CVE-2026-32170, an elevation-of-privilege vulnerability in the Windows Rich Text Edit Control. The flaw, disclosed in the Microsoft Security...
Microsoft Fixes Critical Windows Admin Center Flaw Allowing SYSTEM-Level Access
Microsoft has disclosed a critical elevation-of-privilege vulnerability in Windows Admin Center, tracked as CVE-2026-35438, that allows a low-privileged attacker to escalate to SYSTEM privileges by...
CVE-2026-35420 Under Active Attack: Patch Windows Kernel EoP Now
Microsoft's May 2026 Patch Tuesday cycle delivered a critical fix for CVE-2026-35420, a Windows Kernel elevation-of-privilege vulnerability with confirmed active exploitation. The flaw allows an...
Microsoft Patches CVE-2026-35418: Elevation-of-Privilege in Windows Cloud Files Driver
On May 12, 2026, Microsoft disclosed CVE-2026-35418, a serious elevation-of-privilege vulnerability that affects the Windows Cloud Files Mini Filter Driver. The flaw, which received an \"Important\"...
Microsoft Confirms Critical Windows Storage Spaces EoP Flaw—Patch Now
Microsoft dropped a stark warning this week: CVE-2026-35415 is not a drill. The vulnerability in Windows Storage Spaces Controller could hand attackers full system control, and the clock is ticking...
Microsoft Patches Important Win32k Elevation of Privilege Flaw (CVE-2026-34347) – Update Now
Microsoft has patched a use-after-free vulnerability in the Windows Win32k kernel driver that could allow a local attacker to gain SYSTEM-level privileges. The flaw, tracked as CVE-2026-34347, was...
CVE-2026-34344: AFD WinSock Privilege Escalation – Critical Fix in May 2026 Patch Tuesday
Microsoft dropped its May 2026 Patch Tuesday updates on May 12, and among the security bulletins is a notable elevation-of-privilege flaw in a core Windows driver. Tracked as CVE-2026-34344, the...
Windows Print Spooler Race Condition EoP Flaw (CVE-2026-34342) Patched
Microsoft shipped a fix for a local privilege escalation flaw in the Windows Print Spooler service on May 12, 2026. Tracked as CVE-2026-34342, the vulnerability enables an authenticated attacker to...
CVE-2026-33839 Win32k Race Flaw Grants SYSTEM Access—Patch Now
Microsoft has addressed a high-severity elevation-of-privilege vulnerability in the Windows graphics system, urging all users to apply the May 2026 security patches immediately. Tracked as...