Skip to content
ThreatCluster

Multiple CVEs Affect Windows Services with Elevation of Privileges

First seen 11 Sep 2026, 18:03 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 20:35 UTC
  • CVE-2026-61349 allows elevation to SYSTEM privileges in Windows Work Folder Service.
  • CVE-2026-54124 enables unauthorized code execution in Windows Terminal.
  • Both vulnerabilities have patches available; users should update immediately.

Two critical vulnerabilities, CVE-2026-61349 and CVE-2026-54124, were disclosed by Microsoft on September 11, 2026. CVE-2026-61349, a use-after-free vulnerability in the Windows Work Folder Service, allows an authorized attacker to elevate privileges to SYSTEM level. CVE-2026-54124, an integer overflow vulnerability in Windows Terminal, enables unauthorized code execution locally. Both vulnerabilities have been acknowledged and updated in Microsoft's advisory. The vulnerabilities affect various Windows services, posing significant risks to users and organizations. Microsoft has released updates to mitigate these issues, and users are urged to apply them promptly. The current status indicates no active exploitation reported as of the latest update.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-14
CVE-2026-54124 published
Microsoft disclosed an integer overflow vulnerability in Windows Terminal that allows unauthorized code execution.
Api.Msrc.Microsoft
2026-08-11
CVE-2026-61349 published
Microsoft disclosed a use-after-free vulnerability in Windows Work Folder Service, allowing privilege escalation.
Api.Msrc.Microsoft
2026-09-11
Vulnerabilities updated
Microsoft updated its advisory for both CVEs, confirming the release of patches and mitigation recommendations.
Api.Msrc.Microsoft

More articles in this cluster (4)