ThreatCluster

Multiple Vulnerabilities in Capability Access Management Service (camsvc)

First seen 13 Jan 2026, 20:07 UTC Api.Msrc.Microsoft 35

Article Content

Browse articles
ThreatCluster

Several vulnerabilities have been identified in the Capability Access Management Service (camsvc), including two elevation of privilege vulnerabilities (CVE-2026-20830, CVE-2026-20815, CVE-2026-21221) and two information disclosure vulnerabilities (CVE-2026-20851, CVE-2026-20835). These vulnerabilities allow authorized and unauthorized attackers to elevate privileges and disclose information locally, respectively, due to improper synchronization and out-of-bounds read issues.