ThreatCluster

Critical Zero-Day Vulnerability in Windows CTFMON Disclosed

First seen 10 Jun 2026, 18:44 UTC GbhackersCybersecuritynews 89% similarity 72

Article Content

Browse articles
ThreatCluster

On June 9, 2026, Microsoft published a security update addressing a zero-day vulnerability in the Windows Collaborative Translation Framework (CTFMON), tracked as CVE-2026-45586. This flaw allows local attackers with low privileges to escalate their access to SYSTEM level, posing a significant risk for exploitation. The vulnerability is rated as 'Important' with a CVSS score of 7.8, indicating a serious threat to affected systems. Windows administrators are urged to deploy the security updates immediately to mitigate potential attacks. The flaw's exploitation could lead to unauthorized access and control over vulnerable systems, making it a valuable target for threat actors. As of the publication date, there are no confirmed reports of active exploitation, but the potential for misuse remains high.

Key Points: • CVE-2026-45586 allows local privilege escalation to SYSTEM level. • Microsoft rated the vulnerability as 'Important' with a CVSS score of 7.8. • Immediate deployment of security updates is recommended for Windows administrators.

ThreatCluster AI

Timeline

2026-06-09
CVE-2026-45586 published
Microsoft disclosed a zero-day vulnerability in Windows CTFMON that enables local privilege escalation.
Cybersecuritynews
2026-06-09
Security updates released
Microsoft released security updates to address the newly disclosed zero-day vulnerability in CTFMON.
Gbhackers

Community

Browse all →