ZeroHour

CVE-2026-70584

mass

Type Confusion Local Privilege Escalation in Microsoft Windows Core Messaging

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-70584 is a type confusion flaw (CWE-843) in the Windows Core Messaging component, where the component accesses a resource using an incompatible type. An attacker who already holds low-privileged access on a local system can trigger the issue, and no user interaction is required. Successful exploitation elevates the attacker's privileges locally, with high impact on the confidentiality, integrity, and availability of the host. Any Windows system containing the affected Core Messaging component is potentially exposed, though the specific affected Windows version ranges are not stated in the available data and should be confirmed against Microsoft's advisory. As of now there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days, indicating no confirmed exploitation.

What to do: Apply Microsoft's security update for CVE-2026-70584 as soon as it is available, prioritizing multi-user systems where local logon is granted to untrusted users (RDP hosts, terminal/VDI servers, shared workstations). Until patched, restrict local logon rights on such hosts and check Microsoft's advisory for the definitive affected-product and version list. There is no known public PoC or in-the-wild exploitation at this time, so patch on a normal high-severity cycle rather than an emergency basis.

Affected
Microsoft Windows (Core Messaging component)
Estimated exposure
masshundreds of millions of Windows installations (Core Messaging is a core OS component; affected version range unspecified) — The vulnerable component ships with Windows, whose active install base is on the order of a billion desktops and servers, so even the subset of affected versions plausibly exceeds one million systems.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Access of resource using incompatible type ('type confusion') in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.