ZeroHour

CVE-2026-58611

mass

Local Privilege Escalation in Microsoft Xbox Gaming Services (CVE-2026-58611)

CVSS 3.1
7.8 high
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-58611 is an improper authorization flaw (CWE-285) in Microsoft's Xbox Gaming Services on Windows in which the service fails to properly validate authorization for privileged operations. It is triggered locally: an attacker who already has a low-privileged foothold on a machine where the service is installed abuses the service without any user interaction. Successful exploitation elevates the attacker's privileges on the local machine, with high impact on confidentiality, integrity, and availability (CVSS 7.8 High). Potentially affected are Windows 10/11 PCs with the Gaming Service installed, which is typically bundled with the Xbox app, PC Game Pass, and many Microsoft Store games. As of the September 2026 Patch Tuesday there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns only a 0.2% probability of exploitation within 30 days.

What to do: Apply the September 2026 Patch Tuesday and ensure the Microsoft Gaming Services package is current — it normally updates through the Microsoft Store, so also refresh the Store library on endpoints. Prioritize multi-user Windows machines, kiosks, and shared/VDI environments where local low-privileged access is more likely. No workaround is published, so patching is the primary mitigation.

Affected
Microsoft Xbox Gaming Services (Windows)
Estimated exposure
masstens of millions of Windows 10/11 PCs with the Gaming Service installed — Xbox Gaming Services is bundled with the Xbox app, PC Game Pass, and many Microsoft Store games on Windows 10/11, giving an installed base in the tens of millions of devices; because the flaw is local, exposure counts installed systems…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper authorization in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
xbox gaming services
Weakness
CWE-285
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Patch Tuesday - September 2026

Microsoft's September 2026 Patch Tuesday fixes 999 CVEs, a record, with two zero-day privilege escalation flaws already exploited in the wild.

Microsoft published 974 own-product vulnerabilities plus 25 non-Microsoft CVEs, totaling 999 — the most CVEs Microsoft has ever released in a single day. Two flaws are exploited in the wild: CVE-2026-85880, an out-of-bounds write in Windows ALPC granting SYSTEM privileges, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack also leading to SYSTEM. Chrome's V8 zero-day CVE-2026-85046 was patched in Edge on September 2, but Microsoft had not published a corresponding advisory, leaving uncertainty about other Chromium fixes in Edge. October 14 lifecycle changes end servicing for Windows 11 24H2 Home/Pro, Office 2021, and Exchange Server 2016/2019.

Rapid7 Blog · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-85046+10 CVEs