AI analysis
CVE-2026-58611 is an improper authorization flaw (CWE-285) in Microsoft's Xbox Gaming Services on Windows in which the service fails to properly validate authorization for privileged operations. It is triggered locally: an attacker who already has a low-privileged foothold on a machine where the service is installed abuses the service without any user interaction. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 7.8 High). Potentially affected are Windows 10/11 PCs with the Gaming Service installed, which is typically bundled with the Xbox app, PC Game Pass, and many Microsoft Store games. As of the September 2026 Patch Tuesday there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Apply the September 2026 Patch Tuesday and ensure the Microsoft Gaming Services package is current — it normally updates through the Microsoft Store, so also refresh the Store library on endpoints. Prioritize multi-user Windows machines, kiosks, and shared/VDI environments where local low-privileged access is more likely. No workaround is published, so patching is the primary mitigation.
Affected
| Microsoft Xbox Gaming Services (Windows) | — |
Estimated exposure
masstens of millions of Windows 10/11 PCs with the Gaming Service installed — Xbox Gaming Services is bundled with the Xbox app, PC Game Pass, and many Microsoft Store games on Windows 10/11, giving an installed base in the tens of millions of devices; because the flaw is local, exposure counts installed systems…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.