CVE-2026-70584
massType Confusion Local Privilege Escalation in Microsoft Windows Core Messaging
CVE-2026-70584 is a type confusion flaw (CWE-843) in the Windows Core Messaging component, where the component accesses a resource using an incompatible type. An attacker who already holds low-privileged access on a local system can trigger the issue, and no user interaction is required. Successful exploitation elevates the attacker's privileges locally, with high impact on the confidentiality, integrity, and availability of the host. Any Windows system containing the affected Core Messaging component is potentially exposed, though the specific affected Windows version ranges are not stated in the available data and should be confirmed against Microsoft's advisory. As of now there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days, indicating no confirmed exploitation.
What to do: Apply Microsoft's security update for CVE-2026-70584 as soon as it is available, prioritizing multi-user systems where local logon is granted to untrusted users (RDP hosts, terminal/VDI servers, shared workstations). Until patched, restrict local logon rights on such hosts and check Microsoft's advisory for the definitive affected-product and version list. There is no known public PoC or in-the-wild exploitation at this time, so patch on a normal high-severity cycle rather than an emergency basis.
| Microsoft Windows (Core Messaging component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.