CVE-2026-56198
massOut-of-bounds Read Local Privilege Escalation in Microsoft Trace Data Helper
Microsoft Trace Data Helper contains an out-of-bounds read (CWE-125) that an authorized local attacker — one who already holds limited privileges on the machine — can trigger without any user interaction. By inducing the component to read beyond a buffer's boundary, the attacker can leverage the flaw to elevate privileges locally, gaining higher rights with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, high). Only systems where Microsoft Trace Data Helper is present are affected; the provided data does not specify which Microsoft products or version ranges ship the component, so defenders should consult Microsoft's advisory when scoping. Exploitation status: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so it is currently considered unexploited.
What to do: Apply the Microsoft security update addressing CVE-2026-56198 as soon as it is released through your standard Microsoft update channel; the provided data does not include fixed version numbers. Because the flaw requires pre-existing low-privileged local access, prioritize hosts where untrusted or multiple users hold local logon or RDP access, and check whether Trace Data Helper is present when scoping.
| Microsoft Trace Data Helper | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.