ZeroHour

CVE-2026-56198

mass

Out-of-bounds Read Local Privilege Escalation in Microsoft Trace Data Helper

CVSS 3.1
7.8 high
EPSS
<1%p16
Published
()
Modified
AI analysis

Microsoft Trace Data Helper contains an out-of-bounds read (CWE-125) that an authorized local attacker — one who already holds limited privileges on the machine — can trigger without any user interaction. By inducing the component to read beyond a buffer's boundary, the attacker can leverage the flaw to elevate privileges locally, gaining higher rights with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 7.8, high). Only systems where Microsoft Trace Data Helper is present are affected; the provided data does not specify which Microsoft products or version ranges ship the component, so defenders should consult Microsoft's advisory when scoping. Exploitation status: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days, so it is currently considered unexploited.

What to do: Apply the Microsoft security update addressing CVE-2026-56198 as soon as it is released through your standard Microsoft update channel; the provided data does not include fixed version numbers. Because the flaw requires pre-existing low-privileged local access, prioritize hosts where untrusted or multiple users hold local logon or RDP access, and check whether Trace Data Helper is present when scoping.

Affected
Microsoft Trace Data Helper
Estimated exposure
massplausibly hundreds of millions of Windows installations (estimate; assumes the component ships broadly with Windows or a widely deployed Microsoft product,… — Microsoft's Windows installed base is on the order of 1.4 billion devices and local privilege-escalation fixes for Microsoft platform components typically apply wherever the component ships, so the affected population plausibly exceeds 1…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.

Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.