Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches Critical AFD.sys Privilege Escalation Vulnerability CVE-2026-24293 in March 2026 Emergency Update
Microsoft released emergency security fixes on March 10, 2026, addressing CVE-2026-24293, a high-impact elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock...
CVE-2026-24290: Windows ProjFS Kernel Privilege Escalation Vulnerability Analysis
Microsoft has assigned CVE-2026-24290 to a newly discovered elevation of privilege vulnerability in the Windows Projected File System (ProjFS) driver. The vulnerability allows authenticated attackers...
CVE-2026-24285: Critical Win32k Local Privilege Escalation Vulnerability Patched by Microsoft
Microsoft has patched a critical local privilege escalation vulnerability in the Windows Win32k subsystem, tracked as CVE-2026-24285. This security flaw allows authenticated local users to gain...
Microsoft Patches Critical ReFS Privilege Escalation Vulnerability CVE-2026-23673
Microsoft released a critical security update on March 10, 2026, addressing CVE-2026-23673, a local elevation-of-privilege vulnerability in the Windows Resilient File System (ReFS). The...
Windows Bluetooth RFCOMM Driver Race Condition Exposes Kernel to Privilege Escalation Attacks
Microsoft has disclosed a critical kernel-level vulnerability in the Windows Bluetooth RFCOMM Protocol Driver that enables local privilege escalation attacks. CVE-2026-23671 represents a race...
CVE-2026-23660: Windows Admin Center Azure Portal Privilege Escalation Vulnerability Explained
Microsoft's security tracker lists CVE-2026-23660 as an elevation of privilege vulnerability affecting Windows Admin Center when accessed through the Azure Portal. The vulnerability appears in...
CVE-2026-26125: Microsoft Flags Critical Payment Flaw with High Confidence Metric
Microsoft has disclosed a critical elevation-of-privilege vulnerability in its Payment Orchestrator Service, designated CVE-2026-26125, with the company assigning a high confidence rating to its...
Azure Compute Gallery regex flaw lets authenticated attackers gain local admin rights
Microsoft has disclosed a significant security vulnerability in Azure Compute Gallery that could allow authenticated attackers to escalate privileges locally within cloud environments....
CVE-2026-26119 in Windows Admin Center lets low-privileged users gain admin rights; patch now
Microsoft has issued an urgent security update addressing a critical privilege escalation vulnerability in Windows Admin Center (WAC) tracked as CVE-2026-26119, which could allow authenticated...
CVE-2026-26119: Critical Windows Admin Center Privilege Escalation Vulnerability Patched
Microsoft has issued an urgent security update addressing a critical privilege escalation vulnerability in Windows Admin Center (WAC) tracked as CVE-2026-26119, which carries a CVSS score of 8.8...
CVE-2025-49809: Critical MTR Privilege Escalation Bug Fixed - Windows Security Alert
A critical security vulnerability in the widely-used network diagnostic tool MTR (My TraceRoute) has been patched after researchers discovered it could allow attackers to execute arbitrary code with...
MySQL CVE-2025-50077: Critical DoS Vulnerability in InnoDB/Optimizer Paths
A newly disclosed critical vulnerability in MySQL Server, tracked as CVE-2025-50077, allows high-privileged attackers to cause sustained denial-of-service conditions by exploiting flaws in the...