ThreatCluster

Multiple Local Privilege Escalation Vulnerabilities in Microsoft Windows

First seen 8 Sep 2026, 22:13 UTC Zerodayinitiativewww.cve.orgmsrc.microsoft.com 45

Article Content

Browse articles
ThreatCluster

Four local privilege escalation vulnerabilities have been identified in Microsoft Windows, all stemming from improper object management within the win32kfull driver. These vulnerabilities, identified as ZDI-26-618, ZDI-26-619, ZDI-26-620, and ZDI-26-621, allow local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM. An attacker must first execute low-privileged code to exploit these vulnerabilities. Microsoft has issued updates to correct these issues. The vulnerabilities were reported to the vendor on May 11, 2026, and the advisories were publicly released on September 8, 2026. The affected systems are various installations of Microsoft Windows. The vulnerabilities have not been reported as actively exploited in the wild.

Key Points: • Four critical local privilege escalation vulnerabilities identified in Microsoft Windows. • Exploitation requires low-privileged code execution on the target system. • Microsoft has released updates to mitigate these vulnerabilities.

Ask AI about this cluster

Timeline

2026-05-11
Vulnerabilities reported to Microsoft
Four vulnerabilities were disclosed to Microsoft for remediation, allowing local privilege escalation.
Zerodayinitiative
2026-09-08
Public release of advisories
Microsoft publicly released advisories for four local privilege escalation vulnerabilities.
Zerodayinitiative
2026-09-08
Advisories updated
Advisories for the vulnerabilities were updated with additional information on mitigation.
Zerodayinitiative